exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

ew_file_manager.txt

ew_file_manager.txt
Posted Jul 26, 2004
Authored by Sullo | Site cirt.net

The EasyWeb FileManager Module for PostNuke is vulnerable to a directory traversal problem which allows retrieval of arbitrary files from the remote system. Versions affected: EasyWeb FileManager 1.0 RC-1.

tags | exploit, remote, arbitrary
SHA-256 | 303f3fe96f6776b82f0eb5c7e944c6c222704eb9f590c10ad306018b5ee14b58

ew_file_manager.txt

Change Mirror Download
* CIRT-200404: EasyWeb (EW) FileManager Directory Traversal *

Remote File Retrieval - 07/23/2004

*Product: *
EasyWeb FileManager Module <http://home.postnuke.ru/>

*Description:*
EasyWeb FileManager Module for PostNuke is vulnerable to a directory
traversal problem which allows retrieval of arbitrary files from the
remote system.

*Systems Affected:*
EasyWeb FileManager 1.0 RC-1

*Technical Description:*
The PostNuke module works by loading a directory and/or file via the
"pathext" (directory) and "view" (file) variables. Providing a relative
path (from the document repository) in the "pathext" variable will cause
FileManager to provide a directory listing of that diretory. Selecting a
file in that listing, or putting a file name in the "view" variable,
will cause EasyWeb to load the file specified. Only files and
directories which can be read by the system user running PHP can be
retrieved.

This URL will show the /etc direcotry (assuming PostNuke is installed at
the root level):

* http://[victim]/index.php?module=ew_filemanager&type=admin&func=manager&pathext=../../../etc


This URL will show the /etc/passwd file (assuming PostNuke is installed
at the root level):

* http://[victim]/index.php?module=ew_filemanager&type=admin&func=manager&pathext=../../../etc/&view=passwd


*Fix/Workaround:*
Use another file manager module for PostNuke, as the authors do not
appear to be maintaining FileManager.

*Vendor Status:*
Vendor was contacted but did not respond.

*Contacts:*
sullo@cirt.net <mailto:sullo@cirt.net>

*References:*
Updated information can be found on OSVDB.org <http://www.osvdb.org/>
under the following entries:
OSVDB-8193 <http://www.osvdb.org/8193> EasyWeb FileManager Directory
Traversal
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close