Cobalt RaQ siteUserMod.cgi Privelege Escalation Vulnerability

BID:951

Info

Cobalt RaQ siteUserMod.cgi Privelege Escalation Vulnerability

Bugtraq ID: 951
Class: Access Validation Error
CVE:
Remote: Yes
Local: Yes
Published: Jan 27 2000 12:00AM
Updated: Jan 27 2000 12:00AM
Credit: Discovered by [email protected]. Posted to Bugtraq on Janurary 28, 2000 by Chuck Pitre <[email protected]>.
Vulnerable: Cobalt RaQ 3.0
Cobalt RaQ 2.0
Cobalt RaQ 1.1
Not Vulnerable:

Discussion

Cobalt RaQ siteUserMod.cgi Privelege Escalation Vulnerability

Due to authentication weaknesses in '.cobalt/siteUserMod/siteUserMod.cgi/' any user with Site Administrator access to a RaQ 1 or 2 with web administration enabled can elevate themselves to Server Administration access by changing the password of the 'admin' account. On RaQ3 products, a Site Administrator can change the password of any user except 'admin' . This is accomplished by copying and then modifying local copies of two frames of the web administration page, index.htm and right.htm .

Exploit / POC

Cobalt RaQ siteUserMod.cgi Privelege Escalation Vulnerability

Copied verbatim from an email from [email protected] (Linked to in it's entirety in the 'credit' section):

To replicate this bug you must have Site Administrator access to one of the accounts on the server. When you go into the Site Management for a site and select the User Management option, you get a list of the usernames that have been setup for that account. The green pencil edit icon is a command to execute the JavaScript function modify() and it passes the username as the only variable into the function. To properly execute a function from the Location Bar in Netscape, the HTML page has to be the top frame. I simply opened the userList.html file in a new frame. When you type "javascript: modify( 'admin' );" into the Location Bar, the modify() function returns a URL. The URL returned when accessing it from my site is "http://target:81/cgi-bin/.cobalt/siteUserMod/siteUserMod.cgi?username=admin&group=site151&949015199230". This loads a standard Modify User page for the "admin" account. However, when you attempt to change this information by clicking the "Confirm Modify" button, it returns a JavaScript error because the function that it calls upon is dependant on the frame layout of the Site Management page. To overcome this issue I simply downloaded two HTML files to my hard disk. One is the index.html file, other other is the right.html file. I basically changed the index.html file to call upon the URL's on my site and had it load the right.html file locally off my hard disk. I then changed the right.html file to load the URL's on my site but changed the "main" frame source to "http://target:81/cgi-bin/.cobalt/siteUserMod/siteUserMod.cgi?username=admin&group=site151&949015199230" - the Modify User page for the "admin" account. It then loads up with all the correct frames AND the Modify User page for the "admin" account. I very simply just enter a new password for the user and click "Confirm Modify" and presto! The admin password is changed allowing me access to the Server Management page showing all the server's clients, IP addresses, domain names, and ability to access all the client's contact people, telephone numbers, usernames, and passwords. I also could delete any sites/files or downloaded any sites/files. I then had full access via FTP to the site showing the root directory of the server, and the ability to delete any evidence via the /log/ directory.

Solution / Fix

Cobalt RaQ siteUserMod.cgi Privelege Escalation Vulnerability

Solution:
Cobalt has release patches for this issue, available at:

RaQ 1 -
ftp://ftp.cobaltnet.com/pub/experimental/security/siteUserMod/RaQ1-Security-3.6.pkg

RaQ 2 -
ftp://ftp.cobaltnet.com/pub/experimental/security/siteUserMod/RaQ2-Security-2.94.pkg

RaQ 3 -
ftp://ftp.cobaltnet.com/pub/experimental/security/siteUserMod/RaQ3-Security-2.2.pkg

References

Cobalt RaQ siteUserMod.cgi Privelege Escalation Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report