what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

major_rls56.txt

major_rls56.txt
Posted Sep 30, 2008
Authored by David "Aesthetico" Vieira-Kurz | Site majorsecurity.de

moziloWiki versions 1.0.1 and below suffer from directory traversal, cross site scripting, and session fixation vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | dd70b38bb138d0c30f9c05b0e529b68107bda25a14630d9ff1f9bf7c2881f719

major_rls56.txt

Change Mirror Download
[MajorSecurity Advisory #56]moziloWiki - Directory Traversal, XSS and SessionFixation Issues

Details
=======
Product: moziloWiki
Security-Risk: High
Remote-Exploit: yes
Vendor-URL: http://www.mozilo.de/
Vendor-Status: informed
Advisory-Status: published

Credits
============
Discovered by: David Vieira-Kurz
http://www.majorsecurity.de

Affected Products:
----------------------------
moziloWiki 1.0.1 and prior

Original Advisory:
============
http://www.majorsecurity.de/index_2.php?major_rls=major_rls56

Introduction
============
moziloWiki is an easy to handle wiki system.

More Details
============
1. Directory Traversal:
----------------------
Affected files:
print.php -> page parameter

Acquiring access to known files outside of the web root and current directory
is possible through directory traversal techniques.
This is made possible through the use of "../../" in a HTTP request.

2. Cross Site Scripting:
----------------------
Affected files:
index.php -> action parameter
index.php -> page parameter

Affected parameters are not being properly sanitised before being returned to the user.
This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

3. session fixation:
---------------------
The "PHPSESSID" parameter can be set to a malicious and arbitrary value.

3.1 Description:
In a session fixation attack, the attacker fixes the user's session ID before the user even logs into the target server.
After a user's session ID has been fixed, the attacker will wait for them to login.
Once the user does so, the attacker uses the predefined session ID value to assume their online identity.

3.2 PoC:
============
http://localhost/mozilowiki/?PHPSESSID=15031988

4. Workaround:
================
Update to mozilowiki 1.0.2

History/Timeline
================
17.09.2008 discovery of the vulnerabilities
18.09.2008 additional tests with other versions
19.09.2008 contacted the vendor
20.09.2008 vendor confirmed vulnerabilities
27.09.2008 vendor released patch
29.09.2008 advisory is written
30.09.2008 advisory released


MajorSecurity
================
MajorSecurity is a German penetrationtesting and security research company which focuses
on web application security. We offer professional penetrationtestings and reliable proof
of concepts.
You will find more Information about MajorSecurity at
http://www.majorsecurity.de/penetrationstest/penetrationtest.php
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    16 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close