StepWeb Search Engine Admin Webpage Access Vulnerability
BID:4503
Info
StepWeb Search Engine Admin Webpage Access Vulnerability
| Bugtraq ID: | 4503 |
| Class: | Design Error |
| CVE: |
CVE-2002-0537 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 12 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovery of this issue is credited to "BrainRawt ." <[email protected]>. |
| Vulnerable: |
Stepweb SWS 2.5 |
| Not Vulnerable: | |
Discussion
StepWeb Search Engine Admin Webpage Access Vulnerability
StepWeb Search Engine (SWS) is a search engine script which uses a flatfile database to store search entries. It is written in Perl and should run on most Unix and Linux variants.
A remote attacker who can guess the location of the admin webpage can trivially gain access to the administrative functions of the software. This is due to the fact that the password credentials for administrative scripts are included in hard-coded links on the admin webpage.
This may enable an attacker to add arbitrary search entries or gain access to search logs.
This issue has been reported for the free version of SWS 2.5. Earlier versions/commercial versions may also be affected.
StepWeb Search Engine (SWS) is a search engine script which uses a flatfile database to store search entries. It is written in Perl and should run on most Unix and Linux variants.
A remote attacker who can guess the location of the admin webpage can trivially gain access to the administrative functions of the software. This is due to the fact that the password credentials for administrative scripts are included in hard-coded links on the admin webpage.
This may enable an attacker to add arbitrary search entries or gain access to search logs.
This issue has been reported for the free version of SWS 2.5. Earlier versions/commercial versions may also be affected.
Exploit / POC
StepWeb Search Engine Admin Webpage Access Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
Solution / Fix
StepWeb Search Engine Admin Webpage Access Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.