Critical Path InJoin Directory Server File Disclosure Vulnerability
BID:4718
Info
Critical Path InJoin Directory Server File Disclosure Vulnerability
| Bugtraq ID: | 4718 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0786 |
| Remote: | Yes |
| Local: | No |
| Published: | May 10 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Credited to Nomad Mobile Research Centre. |
| Vulnerable: |
Critical Path InJoin Directory Server 4.0 |
| Not Vulnerable: | |
Discussion
Critical Path InJoin Directory Server File Disclosure Vulnerability
Critical Path provides an LDAP (Lightweight Directory Access Protocol) Directory Server called InJoin. InJoin Directory Server is provided for Microsoft Windows operating systems and Unix variants. iCon is the administrative web interface for the inJoin Directory Server.
An attacker with a valid administrative username and password is able to view any file on the system that is accessible to the owner of the iCon process. The contents of arbitrary webserver readable files can be disclosed by supplying their path as the log entry parameter when viewing log entries.
Critical Path provides an LDAP (Lightweight Directory Access Protocol) Directory Server called InJoin. InJoin Directory Server is provided for Microsoft Windows operating systems and Unix variants. iCon is the administrative web interface for the inJoin Directory Server.
An attacker with a valid administrative username and password is able to view any file on the system that is accessible to the owner of the iCon process. The contents of arbitrary webserver readable files can be disclosed by supplying their path as the log entry parameter when viewing log entries.
Exploit / POC
Critical Path InJoin Directory Server File Disclosure Vulnerability
The following examples were provided as a proof-of-concept:
http://ip:1500/CONF&LOG=/etc/passwd&NOIH=no&FRAMES=y
Here the attacker is able to view the contents of /etc/passwd.
The following examples were provided as a proof-of-concept:
http://ip:1500/CONF&LOG=/etc/passwd&NOIH=no&FRAMES=y
Here the attacker is able to view the contents of /etc/passwd.
Solution / Fix
Critical Path InJoin Directory Server File Disclosure Vulnerability
Solution:
Critical Path is aware of the vulnerability. A maintenance release to be known as iCon 4.1.4.7 will be posted on the Critical Path support website in the near future. Please contact Critical Path for more information about the availability of the maintenance release.
Solution:
Critical Path is aware of the vulnerability. A maintenance release to be known as iCon 4.1.4.7 will be posted on the Critical Path support website in the near future. Please contact Critical Path for more information about the availability of the maintenance release.
References
Critical Path InJoin Directory Server File Disclosure Vulnerability
References:
References:
- Critical Path Support Page (Critical Path)