Umapresence Local File Include and Arbitrary File Deletion Vulnerabilities
BID:54194
Info
Umapresence Local File Include and Arbitrary File Deletion Vulnerabilities
| Bugtraq ID: | 54194 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 25 2012 12:00AM |
| Updated: | Jun 25 2012 12:00AM |
| Credit: | Sammy FORGIT |
| Vulnerable: |
Umazuma Umapresence 2.6 |
| Not Vulnerable: | |
Discussion
Umapresence Local File Include and Arbitrary File Deletion Vulnerabilities
Umapresence is prone to a local file-include vulnerability and an arbitrary file-deletion vulnerability because the application fails to sufficiently sanitize user-supplied input.
An attacker can exploit a local file-include vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the web server process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.
Attackers can exploit an arbitrary file-deletion vulnerability with directory-traversal strings ('../') to delete arbitrary files; this may aid in launching further attacks.
Umapresence 2.6.0 is vulnerable; other versions may also be affected.
Umapresence is prone to a local file-include vulnerability and an arbitrary file-deletion vulnerability because the application fails to sufficiently sanitize user-supplied input.
An attacker can exploit a local file-include vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the web server process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.
Attackers can exploit an arbitrary file-deletion vulnerability with directory-traversal strings ('../') to delete arbitrary files; this may aid in launching further attacks.
Umapresence 2.6.0 is vulnerable; other versions may also be affected.
Exploit / POC
Umapresence Local File Include and Arbitrary File Deletion Vulnerabilities
An attacker can exploit these issues through a browser.
The following example URI is available:
http://www.example.com/umapresence/umaservices/uma_editor/inc/insert_doc.pop.php?dos=../../style
An attacker can exploit these issues through a browser.
The following example URI is available:
http://www.example.com/umapresence/umaservices/uma_editor/inc/insert_doc.pop.php?dos=../../style
Solution / Fix
Umapresence Local File Include and Arbitrary File Deletion Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Umapresence Local File Include and Arbitrary File Deletion Vulnerabilities
References:
References:
- Umapresence Homepage (Umazuma)