evolve or die

websiteBaker.txt

websiteBaker.txt
Posted Aug 5, 2005
Authored by tgo

The Website Baker Project is susceptible to path disclosure and cross site scripting vulnerabilities.

tags | advisory, vulnerability, xss
MD5 | 592786bb447195f1b20f943929fd3437

websiteBaker.txt

Change Mirror Download
----------------------------------------------------------
Website Baker Project Multiple Vulnerabilities
----------------------------------------------------------

Vulnerabilities
---------------

1) admin/media/browse.php

The "dir" parameter is vulnerable to xss. Also the script blocks ../ but if a non-existant

directory is chosen the script tries to read it and the error gives path disclosure.

2) 25 accounts of path disclosure when a file is directly accessed. There is too many too list so

I will just leave them out.

3) In admin/media users are allowed to upload media for their site. This area is supposed to be

for picture and maybe songs, but the final extension is not checked and php files are able to be

uploaded and executed on the server. Even though its in the admin directory regular users can use

this feauture if the admin allows it, so site admins should be aware of this.

Solutions
---------

1) Check to see if the directory exists before trying to read from it. Strip tags from the

variable to stop the xss.

2) Check to see if a file is directly accessed and if it is have the script die.

3) Edit the source code to disallow file extensions that could lead to malicious scripts being

run on the server.

Credit
------

thegreatone2176

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close