Douran Portal 'download.aspx' Arbitrary File Download Vulnerability
BID:46927
Info
Douran Portal 'download.aspx' Arbitrary File Download Vulnerability
| Bugtraq ID: | 46927 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-1569 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 21 2011 12:00AM |
| Updated: | Apr 13 2015 09:01PM |
| Credit: | AJAX Security Team |
| Vulnerable: |
Douran Portal Douran Portal 3.9.7 8 Douran Portal Douran Portal 3.9 23 Douran Portal Douran Portal 3.9.7.55 Douran Portal Douran Portal 3.9.6.0 Douran Portal Douran Portal 3.9.5.0.1 |
| Not Vulnerable: |
Douran Portal Douran Portal 3.9.8.0 |
Discussion
Douran Portal 'download.aspx' Arbitrary File Download Vulnerability
Douran Portal is prone to a vulnerability that lets attackers download arbitrary files. This issue occurs because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary files within the context of the application. Information harvested may aid in launching further attacks.
Douran Portal 3.9.7.8 is affected; other versions may also be vulnerable.
Douran Portal is prone to a vulnerability that lets attackers download arbitrary files. This issue occurs because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary files within the context of the application. Information harvested may aid in launching further attacks.
Douran Portal 3.9.7.8 is affected; other versions may also be vulnerable.
Exploit / POC
Douran Portal 'download.aspx' Arbitrary File Download Vulnerability
An attacker can exploit this issue using a browser.
The following example URI is available:
http://www.example.com/download.aspx?FilePathAttach=/&FileNameAttach=web.config\.&OriginalAttachFileName=secretfile.txt
An attacker can exploit this issue using a browser.
The following example URI is available:
http://www.example.com/download.aspx?FilePathAttach=/&FileNameAttach=web.config\.&OriginalAttachFileName=secretfile.txt
Solution / Fix
Douran Portal 'download.aspx' Arbitrary File Download Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Douran Portal 'download.aspx' Arbitrary File Download Vulnerability
References:
References:
- Douran Portal Homepage (Douran Portal)