- 전체
- 보안뉴스
- 제로데이취약점
- 해킹프로그래밍
- 웹해킹
- 해킹기법
- 정보보호
- 정보보안기사 - 국가기술자격
- 악성코드분석_리버싱
- 시큐어코딩_개발보안진단원
- CISSP
- CISA
- 모의해킹_penetration-test
- deepweb / tor network
- Kali Linux
제로데이취약점 XAMPP 1.8.1 (lang.php, WriteIntoLocalDisk method) - Local Write Access Vulnerability
2013.10.17 00:10
XAMPP 1.8.1 (lang.php, WriteIntoLocalDisk method) - Local Write Access Vulnerability
=============================================INTERNET SECURITY AUDITORS ALERT 2013-007- Original release date: March 14th, 2013- Last revised: March 19th, 2013- Discovered by: Manuel García Cárdenas- Severity: 6,8/10 (CVSS Base Score)- CVE-ID: CVE-2013-2586=============================================I. VULNERABILITY-------------------------XAMPP 1.8.1 Local Write Access VulnerabilityII. BACKGROUND-------------------------XAMPP is a free and open source cross-platform web server solution stackpackage, consisting mainly of the Apache HTTP Server, MySQL database, andinterpreters for scripts written in the PHP and Perl programming languages.III. DESCRIPTION-------------------------It has been detected than an unprivileged user can write in the localdisk and the local file "lang.tmp" can be modified in the remote machine.The injection is done through the page "/xampp/lang.php".IV. PROOF OF CONCEPT-------------------------Malicious Requesthttp://vulnerablesite.com/xampp/lang.php?WriteIntoLocalDiskAnd next, if we access to the file:http://vulnerablesite.com/xampp/lang.tmpWe can verify that the file was modified.V. BUSINESS IMPACT-------------------------An attacker can execute arbitrary HTML or script code in a targeteduser's browser, this can leverage to steal sensitive information as usercredentials,personal data, etc.VI. SYSTEMS AFFECTED-------------------------XAMPP 1.8.1VII. SOLUTION-------------------------All data received by the application that can be modified by the usermust be validated.VIII. REFERENCES-------------------------http://www.apachefriends.orghttp://www.isecauditors.comIX. CREDITS-------------------------This vulnerability has been discoveredby Manuel García Cárdenas (mgarcia (at) isecauditors (dot) com).X. REVISION HISTORY------------------------March 14, 2013: Initial releaseSeptember 26, 2013: Final releaseXI. DISCLOSURE TIMELINE-------------------------March 14, 2013: Vulnerability acquired by Internet SecurityAuditors (www.isecauditors.com).March 16, 2013: CVE-ID received.March 18, 2013: Sent to Development Manager.August 30, 2013: New version that includes patched code.September 26, 2013: Sent to lists.XII. LEGAL NOTICES-------------------------The information contained within this advisory is supplied "as-is" withno warranties or guarantees of fitness of use or otherwise. InternetSecurityAuditors accepts no responsibility for any damage caused by the use ormisuse of this information.XIII. ABOUT-------------------------Internet Security Auditors is a Spain based leader in web applicationtesting, network security, penetration testing, security complianceimplementation andassessing. Our clients include some of the largest companies in areassuch as finance, telecommunications, insurance, ITC, etc. We are vendorindependentprovider with a deep expertise since 2001. Our efforts in R&D includevulnerability research, open security project collaboration andwhitepapers,presentations and security events participation and promotion. Forfurther information regarding our security services, contact us.XIV. FOLLOW US-------------------------You can follow Internet Security Auditors, news and security advisories at:https://www.facebook.com/ISecAuditorshttps://twitter.com/ISecAuditorshttp://www.linkedin.com/company/internet-security-auditorshttp://www.youtube.com/user/ISecAuditors |
본 웹사이트는 광고를 포함하고 있습니다.
광고 클릭에서 발생하는 수익금은 모두 웹사이트 서버의 유지 및 관리, 그리고 기술 콘텐츠 향상을 위해 쓰여집니다.
광고 클릭에서 발생하는 수익금은 모두 웹사이트 서버의 유지 및 관리, 그리고 기술 콘텐츠 향상을 위해 쓰여집니다.
댓글 0
| 번호 | 제목 | 글쓴이 | 날짜 | 조회 수 |
|---|---|---|---|---|
| 공지 | 침투테스트(취약점검점검, 모의해킹) 문의 / 답변 | 졸리운_곰 | 2017.12.10 | 28360 |
| 9 |
정보보안기사 합격자 현황 (1회~3회)
| 졸리운_곰 | 2014.10.28 | 339 |
| 8 |
정보보안기사, 정보보안산업기사 출제기준
| 졸리운_곰 | 2014.01.09 | 1641 |
| 7 |
* 정보보안기사 2014년도 시험 일정
| 졸리운_곰 | 2014.01.09 | 1789 |
| 6 | 2013년 제2회 정보보안기사 2차 실기 기출문제 목록 | 가을의 곰을... | 2013.12.09 | 3389 |
| 5 |
정보보안기사 2013년 2회 필기 결과
| 가을의 곰을... | 2013.11.03 | 2634 |
| 4 | [임베스트, 보안기사] 제1회 정보보안기사 시험완료(기출문제) IT자격증 | 가을의 곰을... | 2013.09.03 | 2538 |
| 3 |
[정보보안기사] 1회 1차 필기 B형 가답안
| 가을의 곰을... | 2013.07.31 | 3566 |
| 2 |
SIS 정보보호전문가 1급,2급 공개문제 및 정답
| 가을의 곰을... | 2013.07.06 | 2352 |
| 1 |
[한국인터넷진흥원] 2013년도 정보보안기사, 정보보안산업기사 자격검정 시행 일정입니다.
| 가을의 곰을... | 2013.05.04 | 2968 |

