Advisory ID: HTB23190
Product: eduTrac
Vendor: 7 Media Web Solutions, LLC.
Vulnerable Version(s): 1.1.1-Stable and probably prior
Tested Version: 1.1.1-Stable
Advisory Publication: December 11, 2013 [without technical details]
Vendor Notification: December 11, 2013=20
Vendor Patch: December 16, 2013=20
Public Disclosure: January 2, 2014=20
Vulnerability Type: Path Traversal [CWE-22]
CVE Reference: CVE-2013-7097
Risk Level: Medium=20
CVSSv2 Base Score: 5 (AV:N/AC:L/Au:N/C:P/I:N/A:N)
Solution Status: Fixed by Vendor
Discovered and Provided: High-Tech Bridge Security Research Lab ( https://w=
ww.htbridge.com/advisory/ )=20
---------------------------------------------------------------------------=
--------------------
Advisory Details:
High-Tech Bridge Security Research Lab discovered path traversal vulnerabil=
ity in eduTrac which can be exploited to read arbitrary files on vulnerable=
system with privileges of web server.
1) Path Traversal in eduTrac: CVE-2013-7097
The vulnerability exists due to insufficient filtration of "showmask" HTTP =
GET parameter passed to "/installer/overview.php" script before using it in=
PHP "file_get_contents()" function. A remote attacker can read contents of=
arbitrary files on the target system.
The exploitation example below reads the "/eduTrac/Config/constants.php" fi=
le that contains database login credentials:
http://[host]/installer/overview.php?step=3Dwriteconfig&showmask=3D../../ed=
uTrac/Config/constants.php
---------------------------------------------------------------------------=
--------------------
Solution:
Update eduTrac to version 1.1.2.
More Information:
http://sourceforge.net/projects/edutrac/files/
---------------------------------------------------------------------------=
--------------------
References:
[1] High-Tech Bridge Advisory HTB23190 - https://www.htbridge.com/advisory/=
HTB23190 - Path Traversal in eduTrac.
[2] eduTrac - http://www.7mediaws.org/ - eduTrac is a student information s=
ystem (SIS) for educational institutions to manage faculty, staff, students=
, courses, registrations, enrollment, and more.
[3] Common Vulnerabilities and Exposures (CVE) - http://cve.mitre.org/ - in=
ternational in scope and free for public use, CVE=C2=AE is a dictionary of =
publicly known information security vulnerabilities and exposures.
[4] Common Weakness Enumeration (CWE) - http://cwe.mitre.org - targeted to =
developers and security practitioners, CWE is a formal list of software wea=
kness types.
[5] ImmuniWeb=C2=AE - http://www.htbridge.com/immuniweb/ - is High-Tech Bri=
dge's proprietary web application security assessment solution with SaaS de=
livery model that combines manual and automated vulnerability testing.
---------------------------------------------------------------------------=
--------------------
Disclaimer: The information provided in this Advisory is provided "as is" a=
nd without any warranty of any kind. Details of this Advisory may be update=
d in order to provide as accurate information as possible. The latest versi=
on of the Advisory is available on web page [1] in the References.