Sphera HostingDirector VDS Control Panel Account Configuration Modification Vulnerability
BID:7896
Info
Sphera HostingDirector VDS Control Panel Account Configuration Modification Vulnerability
| Bugtraq ID: | 7896 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 13 2003 12:00AM |
| Updated: | Jun 13 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "Lorenzo Hernandez Garcia-Hierro" <[email protected]>. |
| Vulnerable: |
Sphera HostingDirector 3.0 Sphera HostingDirector 2.0 Sphera HostingDirector 1.0 |
| Not Vulnerable: | |
Discussion
Sphera HostingDirector VDS Control Panel Account Configuration Modification Vulnerability
Sphera HostingDirector VDS Control Panel has been reported prone to a vulnerability where an attacker may make arbitrary account configuration modifications.
It has been reported that an attacker, may connect to the HostingDirector server and spoof HTTP referrer data to bypass HostingDirector authentication systems. It is then possible to make arbitrary modifications to other HostingDirector account configurations.
Sphera HostingDirector VDS Control Panel has been reported prone to a vulnerability where an attacker may make arbitrary account configuration modifications.
It has been reported that an attacker, may connect to the HostingDirector server and spoof HTTP referrer data to bypass HostingDirector authentication systems. It is then possible to make arbitrary modifications to other HostingDirector account configurations.
Exploit / POC
Sphera HostingDirector VDS Control Panel Account Configuration Modification Vulnerability
The following proof of concept has been provided:
http://www.example.com/[INSTALLATION PATH]/dev/VDS/submitted.php?[TARGET
USER]\activeservices\http||watchdog_running=[false]&restart_vds=on&success_m
sg=Remote USER VDS restarted trough this kind of attack/watch dog disabled.
The following proof of concept has been provided:
http://www.example.com/[INSTALLATION PATH]/dev/VDS/submitted.php?[TARGET
USER]\activeservices\http||watchdog_running=[false]&restart_vds=on&success_m
sg=Remote USER VDS restarted trough this kind of attack/watch dog disabled.
Solution / Fix
Sphera HostingDirector VDS Control Panel Account Configuration Modification Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Sphera HostingDirector VDS Control Panel Account Configuration Modification Vulnerability
References:
References:
- HostingDirector Homepage (Sphera)
- Sphera Hosting Director Control Panel Multiple Vulnerabilities ("Lorenzo Hernandez Garcia-Hierro"
)