SmarterStats Multiple Input Validation Vulnerabilities
BID:46840
Info
SmarterStats Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 46840 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 11 2011 12:00AM |
| Updated: | May 18 2011 06:52PM |
| Credit: | Hoyt LLC Research |
| Vulnerable: |
SmarterTools Smarterstats 6.0 |
| Not Vulnerable: | |
Discussion
SmarterStats Multiple Input Validation Vulnerabilities
SmarterStats is prone to the following remote vulnerabilities:
1. Multiple remote command-injection vulnerabilities
2. Multiple SQL-injection vulnerabilities
3. A security-bypass vulnerability
Exploiting these issues could allow an attacker to execute arbitrary code, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database and gain unauthorized access to the affected application.
SmarterStats 6.0 is vulnerable; other versions may also be affected.
SmarterStats is prone to the following remote vulnerabilities:
1. Multiple remote command-injection vulnerabilities
2. Multiple SQL-injection vulnerabilities
3. A security-bypass vulnerability
Exploiting these issues could allow an attacker to execute arbitrary code, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database and gain unauthorized access to the affected application.
SmarterStats 6.0 is vulnerable; other versions may also be affected.
Exploit / POC
SmarterStats Multiple Input Validation Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
1. OS command injection:
http://www.example.com.host:9999/Admin/frmSite.aspx [STTTState cookie]
http://www.example.com.host:9999/Admin/frmSite.aspx [ctl00%24MPH%24txtAdminNewPassword_SettingText parameter]
http://www.example.com.host:9999/Admin/frmSite.aspx [ctl00%24MPH%24txtSmarterLogDirectory parameter]
http://www.example.com.host:9999/Admin/frmSite.aspx [ctl00%24MPH%24ucSiteSeoSearchEngineSettings%24chklistEngines_SettingCheckBox%2414 parameter]
http://www.example.com.host:9999/Admin/frmSite.aspx [ctl00%24MPH%24ucSiteSeoSettings%24txtSeoMaxKeywords_SettingText parameter]
http://www.example.com.host:9999/Admin/frmSite.aspx [ctl00_MPH_grdLogLocations_HiddenLSR parameter]
2. SQL injection:
http://www.example.com.host:9999/Admin/frmSite.aspx [ctl00%24MPH%24txtSmarterLogDirectory parameter]
http://www.example.com.host:9999/Admin/frmSite.aspx [ctl00%24MPH%24ucSiteSeoSettings%24txtSeoMaxCometitors_SettingText parameter]
http://www.example.com.host:9999/Admin/frmSite.aspx [ctl00%24MPH%24ucSiteSeoSettings%24txtSeoMaxKeywords_SettingText parameter]
http://www.example.com.host:9999/Default.aspx [ctl00%24PageTitle parameter]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [ASP.NET_SessionId cookie]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [ASP.NET_SessionId cookie]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [ASP.NET_SessionId cookie]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [Referer HTTP header]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [STHashCookie cookie]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [STHashCookie cookie]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [STTTState cookie]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [STTTState cookie]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [SelectedLanguage cookie]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [SelectedLanguage cookie]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [User-Agent HTTP header]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [loginsettings cookie]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [op parameter]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [op parameter]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [op parameter]
http://www.example.com.host:9999/login.aspx [Referer HTTP header]
http://www.example.com.host:9999/login.aspx [STHashCookie cookie]
http://www.example.com.host:9999/Client/frmViewReports.aspx [ReportType parameter]
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
1. OS command injection:
http://www.example.com.host:9999/Admin/frmSite.aspx [STTTState cookie]
http://www.example.com.host:9999/Admin/frmSite.aspx [ctl00%24MPH%24txtAdminNewPassword_SettingText parameter]
http://www.example.com.host:9999/Admin/frmSite.aspx [ctl00%24MPH%24txtSmarterLogDirectory parameter]
http://www.example.com.host:9999/Admin/frmSite.aspx [ctl00%24MPH%24ucSiteSeoSearchEngineSettings%24chklistEngines_SettingCheckBox%2414 parameter]
http://www.example.com.host:9999/Admin/frmSite.aspx [ctl00%24MPH%24ucSiteSeoSettings%24txtSeoMaxKeywords_SettingText parameter]
http://www.example.com.host:9999/Admin/frmSite.aspx [ctl00_MPH_grdLogLocations_HiddenLSR parameter]
2. SQL injection:
http://www.example.com.host:9999/Admin/frmSite.aspx [ctl00%24MPH%24txtSmarterLogDirectory parameter]
http://www.example.com.host:9999/Admin/frmSite.aspx [ctl00%24MPH%24ucSiteSeoSettings%24txtSeoMaxCometitors_SettingText parameter]
http://www.example.com.host:9999/Admin/frmSite.aspx [ctl00%24MPH%24ucSiteSeoSettings%24txtSeoMaxKeywords_SettingText parameter]
http://www.example.com.host:9999/Default.aspx [ctl00%24PageTitle parameter]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [ASP.NET_SessionId cookie]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [ASP.NET_SessionId cookie]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [ASP.NET_SessionId cookie]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [Referer HTTP header]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [STHashCookie cookie]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [STHashCookie cookie]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [STTTState cookie]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [STTTState cookie]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [SelectedLanguage cookie]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [SelectedLanguage cookie]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [User-Agent HTTP header]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [loginsettings cookie]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [op parameter]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [op parameter]
http://www.example.com.host:9999/Services/SiteAdmin.asmx [op parameter]
http://www.example.com.host:9999/login.aspx [Referer HTTP header]
http://www.example.com.host:9999/login.aspx [STHashCookie cookie]
http://www.example.com.host:9999/Client/frmViewReports.aspx [ReportType parameter]
Solution / Fix
SmarterStats Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
SmarterStats Multiple Input Validation Vulnerabilities
References:
References:
- SmarterStats Homepage (SmarterTools)
- Vulnerability Note VU#240150 SmarterTools default basic web server vulnerabiliti (US-CERT)