Mambo Site Server Cookie Validation Vulnerability
BID:6926
Info
Mambo Site Server Cookie Validation Vulnerability
| Bugtraq ID: | 6926 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 2003 12:00AM |
| Updated: | Feb 24 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Simen Bergo <[email protected]>. |
| Vulnerable: |
Mambo Mambo Site Server 4.0.12 RC2 |
| Not Vulnerable: |
Mambo Mambo Site Server 4.0.12 RC3 Mambo Mambo Site Server 4.0.12 |
Discussion
Mambo Site Server Cookie Validation Vulnerability
Mambo Site Server may grant access without sufficiently validating cookie based authentication credentials. It has been reported that Mambo will accept a user cookie sent by the site as an administrative credential. To exploit this issue, the attacker must receive a cookie (such as the one issued during logout) and then use MD5 to encode their session ID in the cookie. The attacker may then access administrative pages using this cookie.
This issue was reported in Mambo Site Server 4.0.12 RC2. Earlier versions may also be affected.
Mambo Site Server may grant access without sufficiently validating cookie based authentication credentials. It has been reported that Mambo will accept a user cookie sent by the site as an administrative credential. To exploit this issue, the attacker must receive a cookie (such as the one issued during logout) and then use MD5 to encode their session ID in the cookie. The attacker may then access administrative pages using this cookie.
This issue was reported in Mambo Site Server 4.0.12 RC2. Earlier versions may also be affected.
Exploit / POC
Mambo Site Server Cookie Validation Vulnerability
There is no exploit required. The following proof-of-concept was submitted:
There is no exploit required. The following proof-of-concept was submitted:
Solution / Fix
Mambo Site Server Cookie Validation Vulnerability
Solution:
The vendor has addressed this issue in version 4.0.12 RC3.
** Mambo Server 4.0.12 final has now been made available. Users are advised to upgrade their installations to the latest stable release.
Mambo Mambo Site Server 4.0.12 RC2
Solution:
The vendor has addressed this issue in version 4.0.12 RC3.
** Mambo Server 4.0.12 final has now been made available. Users are advised to upgrade their installations to the latest stable release.
Mambo Mambo Site Server 4.0.12 RC2
-
Mambo Mambo Server 4.0.12
http://sourceforge.net/project/showfiles.php?group_id=25577 -
Mambo Site Server MamboV4.0.12-RC3-patch.tar.gz
http://prdownloads.sourceforge.net/mambo/MamboV4.0.12-RC3-patch.tar.gz ?download -
Mambo Site Server Mambo Site Server 4.0.12 RC3
http://prdownloads.sourceforge.net/mambo/MamboV4.0.12-RC3.tar.gz?downl oad
References
Mambo Site Server Cookie Validation Vulnerability
References:
References:
- Mambo Project Homepage (Mambo)
- Mambo SiteServer exploit gains administrative privileges (Simen Bergo
)