Working Resources BadBlue Unauthorized HTS Access Vulnerability
BID:7638
Info
Working Resources BadBlue Unauthorized HTS Access Vulnerability
| Bugtraq ID: | 7638 |
| Class: | Serialization Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 20 2003 12:00AM |
| Updated: | May 20 2003 12:00AM |
| Credit: | Discovery of this issue is credited to "[email protected]" <[email protected]>. |
| Vulnerable: |
Working Resources Inc. BadBlue Personal Edition 2.16 Working Resources Inc. BadBlue Personal Edition 2.15 Working Resources Inc. BadBlue Personal Edition 2.2 Working Resources Inc. BadBlue Personal Edition 2.1 Working Resources Inc. BadBlue Personal Edition 2.0 Working Resources Inc. BadBlue Personal Edition 1.7.4 Working Resources Inc. BadBlue Personal Edition 1.7.3 Working Resources Inc. BadBlue Personal Edition 1.7.2 Working Resources Inc. BadBlue Personal Edition 1.7 Working Resources Inc. BadBlue Enterprise Edition 2.15 Working Resources Inc. BadBlue Enterprise Edition 2.2 Working Resources Inc. BadBlue Enterprise Edition 2.1 Working Resources Inc. BadBlue Enterprise Edition 2.0 Working Resources Inc. BadBlue Enterprise Edition 1.7.4 Working Resources Inc. BadBlue Enterprise Edition 1.7.3 Working Resources Inc. BadBlue Enterprise Edition 1.7.2 Working Resources Inc. BadBlue Enterprise Edition 1.7 |
| Not Vulnerable: |
Working Resources Inc. BadBlue Personal Edition 2.3 Working Resources Inc. BadBlue Enterprise Edition 2.3 |
Discussion
Working Resources BadBlue Unauthorized HTS Access Vulnerability
BadBlue is prone to a vulnerability that could allow remote attackers to gain unauthorized access to administrative functions.
It is possible to bypass BadBlue security checks when '.hts' files are requested by a remote user. BadBlue restricts access to non-HTML files by replacing the first two letters in the file extension of a requested resource with 'ht'. If the third character of a file extension is 's', then it is possible to trick BadBlue into serving a non-HTML file with an extension of '.hts'. This will bypass other security checks which would normally prevent BadBlue from serving these files to remote users.
BadBlue is prone to a vulnerability that could allow remote attackers to gain unauthorized access to administrative functions.
It is possible to bypass BadBlue security checks when '.hts' files are requested by a remote user. BadBlue restricts access to non-HTML files by replacing the first two letters in the file extension of a requested resource with 'ht'. If the third character of a file extension is 's', then it is possible to trick BadBlue into serving a non-HTML file with an extension of '.hts'. This will bypass other security checks which would normally prevent BadBlue from serving these files to remote users.
Exploit / POC
Working Resources BadBlue Unauthorized HTS Access Vulnerability
The issue may be exploited with a web browser. The following example was submitted:
http://www.example.com/ext.dll?mfcisapicommand=loadpage&page=admin.ats&a0=add&a1=root&a2=%5C
This example will reveal the contents of the server's primary volume.
The issue may be exploited with a web browser. The following example was submitted:
http://www.example.com/ext.dll?mfcisapicommand=loadpage&page=admin.ats&a0=add&a1=root&a2=%5C
This example will reveal the contents of the server's primary volume.
Solution / Fix
Working Resources BadBlue Unauthorized HTS Access Vulnerability
Solution:
This issue has been addressed in BadBlue version 2.3. Users should contact the vendor to obtain fixes for the Enterprise Edition.
Working Resources Inc. BadBlue Personal Edition 1.7
Working Resources Inc. BadBlue Personal Edition 1.7.2
Working Resources Inc. BadBlue Personal Edition 1.7.3
Working Resources Inc. BadBlue Personal Edition 1.7.4
Working Resources Inc. BadBlue Personal Edition 2.0
Working Resources Inc. BadBlue Personal Edition 2.1
Working Resources Inc. BadBlue Personal Edition 2.15
Working Resources Inc. BadBlue Personal Edition 2.16
Working Resources Inc. BadBlue Personal Edition 2.2
Solution:
This issue has been addressed in BadBlue version 2.3. Users should contact the vendor to obtain fixes for the Enterprise Edition.
Working Resources Inc. BadBlue Personal Edition 1.7
-
Working Resources Inc. BadBlue Personal Edition 2.3
http://www.badblue.com/down.htm
Working Resources Inc. BadBlue Personal Edition 1.7.2
-
Working Resources Inc. BadBlue Personal Edition 2.3
http://www.badblue.com/down.htm
Working Resources Inc. BadBlue Personal Edition 1.7.3
-
Working Resources Inc. BadBlue Personal Edition 2.3
http://www.badblue.com/down.htm
Working Resources Inc. BadBlue Personal Edition 1.7.4
-
Working Resources Inc. BadBlue Personal Edition 2.3
http://www.badblue.com/down.htm
Working Resources Inc. BadBlue Personal Edition 2.0
-
Working Resources Inc. BadBlue Personal Edition 2.3
http://www.badblue.com/down.htm
Working Resources Inc. BadBlue Personal Edition 2.1
-
Working Resources Inc. BadBlue Personal Edition 2.3
http://www.badblue.com/down.htm
Working Resources Inc. BadBlue Personal Edition 2.15
-
Working Resources Inc. BadBlue Personal Edition 2.3
http://www.badblue.com/down.htm
Working Resources Inc. BadBlue Personal Edition 2.16
-
Working Resources Inc. BadBlue Personal Edition 2.3
http://www.badblue.com/down.htm
Working Resources Inc. BadBlue Personal Edition 2.2
-
Working Resources Inc. BadBlue Personal Edition 2.3
http://www.badblue.com/down.htm
References
Working Resources BadBlue Unauthorized HTS Access Vulnerability
References:
References:
- BadBlue Product Homepage (Working Resources Inc)
- BadBlue Remote Administrative Interface Access Vulnerability ("[email protected]"
)