Hosting Controller DSNManager Directory Traversal Vulnerability
BID:4759
Info
Hosting Controller DSNManager Directory Traversal Vulnerability
| Bugtraq ID: | 4759 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0772 |
| Remote: | Yes |
| Local: | No |
| Published: | May 17 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Discovery of this issue is credited to [email protected] <[email protected]>. |
| Vulnerable: |
Hosting Controller Hosting Controller 1.4.1 Hosting Controller Hosting Controller 1.4 b Hosting Controller Hosting Controller 1.4 Hosting Controller Hosting Controller 1.3 Hosting Controller Hosting Controller 1.1 |
| Not Vulnerable: | |
Discussion
Hosting Controller DSNManager Directory Traversal Vulnerability
Hosting Controller is an application which consolidates all hosting tasks into one interface. Hosting Controller runs on Microsoft Windows operating systems.
The DSNManager script does not sufficiently filter dot-dot-slash (../) sequences from URL parameters, making it prone to directory traversal attacks. An attacker can exploit this condition to disclose the contents of arbitrary web-readable files or potentially add a DSN (Data Source Number) to an arbitrary directory.
Hosting Controller is an application which consolidates all hosting tasks into one interface. Hosting Controller runs on Microsoft Windows operating systems.
The DSNManager script does not sufficiently filter dot-dot-slash (../) sequences from URL parameters, making it prone to directory traversal attacks. An attacker can exploit this condition to disclose the contents of arbitrary web-readable files or potentially add a DSN (Data Source Number) to an arbitrary directory.
Exploit / POC
Hosting Controller DSNManager Directory Traversal Vulnerability
This issue may be exploited with a web browser. The following example was submitted:
http://target/admin/dsn/dsnmanager.asp?
DSNAction=ChangeRoot&RootName=D:\webspace\opendnsserver\targ
et\target.com\db\..\..\..\..\
This issue may be exploited with a web browser. The following example was submitted:
http://target/admin/dsn/dsnmanager.asp?
DSNAction=ChangeRoot&RootName=D:\webspace\opendnsserver\targ
et\target.com\db\..\..\..\..\
Solution / Fix
Hosting Controller DSNManager Directory Traversal Vulnerability
Solution:
A patch has been made available:
Hosting Controller Hosting Controller 1.1
Hosting Controller Hosting Controller 1.3
Hosting Controller Hosting Controller 1.4 b
Hosting Controller Hosting Controller 1.4
Hosting Controller Hosting Controller 1.4.1
Solution:
A patch has been made available:
Hosting Controller Hosting Controller 1.1
-
Hosting Controller dot-slash.zip
http://hostingcontroller.com/english/patches/ForAll/download/dot-slash .zip
Hosting Controller Hosting Controller 1.3
-
Hosting Controller dot-slash.zip
http://hostingcontroller.com/english/patches/ForAll/download/dot-slash .zip
Hosting Controller Hosting Controller 1.4 b
-
Hosting Controller dot-slash.zip
http://hostingcontroller.com/english/patches/ForAll/download/dot-slash .zip
Hosting Controller Hosting Controller 1.4
-
Hosting Controller dot-slash.zip
http://hostingcontroller.com/english/patches/ForAll/download/dot-slash .zip
Hosting Controller Hosting Controller 1.4.1
-
Hosting Controller dot-slash.zip
http://hostingcontroller.com/english/patches/ForAll/download/dot-slash .zip
References
Hosting Controller DSNManager Directory Traversal Vulnerability
References:
References:
- Hosting Controller Homepage (Hosting Controller)