what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

MyBiz MyProcureNet 5.0.0 File Upload / Cross Site Scripting

MyBiz MyProcureNet 5.0.0 File Upload / Cross Site Scripting
Posted May 14, 2018
Authored by Fikri Fadzil, Wan Ikram, Jasveer Singh, Ahmad Ramadhan Amizudin | Site sec-consult.com

MyBiz MyProcureNet version 5.0.0 suffers from remote file upload and cross site scripting vulnerabilities.

tags | advisory, remote, vulnerability, xss, file upload
advisories | CVE-2018-11091, CVE-2018-11090
SHA-256 | 051be9c96f5fc1dcdd65d667cf867817b2d9754a57b28812ac9fe96bc7e1ca84

MyBiz MyProcureNet 5.0.0 File Upload / Cross Site Scripting

Change Mirror Download
SEC Consult Vulnerability Lab Security Advisory < 20180514-0 >
=======================================================================
title: Arbitrary File Upload & Cross-site scripting
product: MyBiz MyProcureNet
vulnerable version: 5.0.0
fixed version: unknown
CVE number: -
impact: Critical
homepage: http://www.mybiz.net/
found: 2018-01-29
by: Ahmad Ramadhan Amizudin (Office Kuala Lumpur)
Fikri Fadzil (Office Singapore)
Wan Ikram (Office Kuala Lumpur)
Jasveer Singh (Office Kuala Lumpur)
SEC Consult Vulnerability Lab

An integrated part of SEC Consult
Europe | Asia | North America

https://www.sec-consult.com

=======================================================================

Vendor description:
-------------------
"MyBiz is a company fixated on developing technology which transforms the way
business is done online. At the intersection of what one business needs from
another is the potential for value to be created differently. This
intersection for the exchange of value requires technology but in
fundamentally very different ways from traditional enterprise systems. MyBiz
believes that the chemistry of business is the business relationships between
enterprises. The strength of the business relationship drives the success and
future of the business. MyBiz believes that these business relationships need
to be captured and orchestrated. MyBiz developed our proprietary Business
Relationship Network engine, a platform to capture business relationships as
data to drive new business services which create value efficiently."

Source: http://www.mybiz.net/copy-of-our-story


Business recommendation:
------------------------
The vendor did not reply to our inquiries since February 2018 hence the issues
might still exist in current versions.

SEC Consult recommends not use this product until a thorough security review
has been performed by security professionals and all identified issues have
been resolved. It is assumed that MyBiz products are affected by further
critical security issues.


Vulnerability overview/description:
-----------------------------------
The identified vulnerabilities can be exploited after authentication but
the registration for the application is usually open for anyone.

1. Arbitrary File Upload
A malicious file can be uploaded to the webserver by an attacker. It is
possible for an attacker to upload a script to issue operating system
commands.

This vulnerability occurs because an attacker is able to adjust the
"HiddenFieldControlCustomWhiteListedExtensions" parameter and add arbitrary
extensions to the whitelist during the upload.

For instance, if the extension .asp is added to the
"HiddenFieldControlCustomWhiteListedExtensions" parameter, the server
accepts "secctest.asp" as legitimate file. Hence malicious files can be
uploaded in order to execute arbitrary commands to take over the server.


2. Reflected Cross-site scripting
This vulnerability within "ProxyPage.aspx" allows an attacker to inject
malicious client side scripting which will be executed in the browser of
users if they visit the manipulated site.


Proof of concept:
-----------------
The proof of concept has been removed as no patch is available.


Vulnerable / tested versions:
-----------------------------
MyBiz MyProcureNet version 5.0.0 has been tested and found to be vulnerable. This
was the latest version available at the time of the test.


Vendor contact timeline:
------------------------
2018-02-22: Contacting vendor through info@mybiz.net (no response)
2018-02-27: Request update from vendor (no response)
2018-03-13: Trying to contact via web form http://www.mybiz.net/contact-us
(no response)
2018-05-14: Public release of security advisory


Solution:
---------
None


Workaround:
-----------
None


Advisory URL:
-------------
https://www.sec-consult.com/en/vulnerability-lab/advisories/index.html

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

SEC Consult Vulnerability Lab

SEC Consult
Europe | Asia | North America

About SEC Consult Vulnerability Lab
The SEC Consult Vulnerability Lab is an integrated part of SEC Consult. It
ensures the continued knowledge gain of SEC Consult in the field of network
and application security to stay ahead of the attacker. The SEC Consult
Vulnerability Lab supports high-quality penetration testing and the evaluation
of new offensive and defensive technologies for our customers. Hence our
customers obtain the most current information about vulnerabilities and valid
recommendation about the risk profile of new technologies.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Interested to work with the experts of SEC Consult?
Send us your application https://www.sec-consult.com/en/career/index.html

Interested in improving your cyber security with the experts of SEC Consult?
Contact our local offices https://www.sec-consult.com/en/contact/index.html
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Mail: research at sec-consult dot com
Web: https://www.sec-consult.com
Blog: http://blog.sec-consult.com
Twitter: https://twitter.com/sec_consult

EOF Ahmad Ramadhan / @2018

Login or Register to add favorites

File Archive:

December 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    0 Files
  • 2
    Dec 2nd
    41 Files
  • 3
    Dec 3rd
    25 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close