- 전체
- 보안뉴스
- 제로데이취약점
- 해킹프로그래밍
- 웹해킹
- 해킹기법
- 정보보호
- 정보보안기사 - 국가기술자격
- 악성코드분석_리버싱
- 시큐어코딩_개발보안진단원
- CISSP
- CISA
- 모의해킹_penetration-test
- deepweb / tor network
- Kali Linux
제로데이취약점 XAMPP 1.8.1 (lang.php, WriteIntoLocalDisk method) - Local Write Access Vulnerability
2013.10.17 00:10
XAMPP 1.8.1 (lang.php, WriteIntoLocalDisk method) - Local Write Access Vulnerability
=============================================INTERNET SECURITY AUDITORS ALERT 2013-007- Original release date: March 14th, 2013- Last revised: March 19th, 2013- Discovered by: Manuel García Cárdenas- Severity: 6,8/10 (CVSS Base Score)- CVE-ID: CVE-2013-2586=============================================I. VULNERABILITY-------------------------XAMPP 1.8.1 Local Write Access VulnerabilityII. BACKGROUND-------------------------XAMPP is a free and open source cross-platform web server solution stackpackage, consisting mainly of the Apache HTTP Server, MySQL database, andinterpreters for scripts written in the PHP and Perl programming languages.III. DESCRIPTION-------------------------It has been detected than an unprivileged user can write in the localdisk and the local file "lang.tmp" can be modified in the remote machine.The injection is done through the page "/xampp/lang.php".IV. PROOF OF CONCEPT-------------------------Malicious Requesthttp://vulnerablesite.com/xampp/lang.php?WriteIntoLocalDiskAnd next, if we access to the file:http://vulnerablesite.com/xampp/lang.tmpWe can verify that the file was modified.V. BUSINESS IMPACT-------------------------An attacker can execute arbitrary HTML or script code in a targeteduser's browser, this can leverage to steal sensitive information as usercredentials,personal data, etc.VI. SYSTEMS AFFECTED-------------------------XAMPP 1.8.1VII. SOLUTION-------------------------All data received by the application that can be modified by the usermust be validated.VIII. REFERENCES-------------------------http://www.apachefriends.orghttp://www.isecauditors.comIX. CREDITS-------------------------This vulnerability has been discoveredby Manuel García Cárdenas (mgarcia (at) isecauditors (dot) com).X. REVISION HISTORY------------------------March 14, 2013: Initial releaseSeptember 26, 2013: Final releaseXI. DISCLOSURE TIMELINE-------------------------March 14, 2013: Vulnerability acquired by Internet SecurityAuditors (www.isecauditors.com).March 16, 2013: CVE-ID received.March 18, 2013: Sent to Development Manager.August 30, 2013: New version that includes patched code.September 26, 2013: Sent to lists.XII. LEGAL NOTICES-------------------------The information contained within this advisory is supplied "as-is" withno warranties or guarantees of fitness of use or otherwise. InternetSecurityAuditors accepts no responsibility for any damage caused by the use ormisuse of this information.XIII. ABOUT-------------------------Internet Security Auditors is a Spain based leader in web applicationtesting, network security, penetration testing, security complianceimplementation andassessing. Our clients include some of the largest companies in areassuch as finance, telecommunications, insurance, ITC, etc. We are vendorindependentprovider with a deep expertise since 2001. Our efforts in R&D includevulnerability research, open security project collaboration andwhitepapers,presentations and security events participation and promotion. Forfurther information regarding our security services, contact us.XIV. FOLLOW US-------------------------You can follow Internet Security Auditors, news and security advisories at:https://www.facebook.com/ISecAuditorshttps://twitter.com/ISecAuditorshttp://www.linkedin.com/company/internet-security-auditorshttp://www.youtube.com/user/ISecAuditors |
본 웹사이트는 광고를 포함하고 있습니다.
광고 클릭에서 발생하는 수익금은 모두 웹사이트 서버의 유지 및 관리, 그리고 기술 콘텐츠 향상을 위해 쓰여집니다.
광고 클릭에서 발생하는 수익금은 모두 웹사이트 서버의 유지 및 관리, 그리고 기술 콘텐츠 향상을 위해 쓰여집니다.
댓글 0
| 번호 | 제목 | 글쓴이 | 날짜 | 조회 수 |
|---|---|---|---|---|
| 공지 | 침투테스트(취약점검점검, 모의해킹) 문의 / 답변 | 졸리운_곰 | 2017.12.10 | 28361 |
| 13 |
[selenium driver를 차단한 사이트의 selenium 접속] How to avoid Selenium webdriver from being detected as bot or web spider
| 졸리운_곰 | 2021.11.27 | 367 |
| 12 |
[웹해킹] iframe Injection
| 졸리운_곰 | 2020.05.10 | 206 |
| 11 |
WebHacking - File Upload 취약점 (우회), Web SHell(웹 쉘)
| 졸리운_곰 | 2018.02.17 | 392 |
| 10 |
WebHacking - PHP File Upload 취약점, 웹 서버 글로벌 설정 파일
| 졸리운_곰 | 2018.02.15 | 492 |
| 9 |
HTTP 응답 분할(HTTP Response Splitting, CRLF) 취약점
| 졸리운_곰 | 2017.04.25 | 915 |
| 8 | CSRF | 졸리운_곰 | 2017.04.09 | 339 |
| 7 |
CSRF공격
| 졸리운_곰 | 2017.04.09 | 6622 |
| 6 |
SQL Injection 공격과 방어 방법 - php, asp 등
| 졸리운_곰 | 2017.01.17 | 1475 |
| 5 |
sqlmap으로 SQL 인젝션 공격 Exploiting A Tricky SQL Injection With sqlmap
| 졸리운_곰 | 2014.11.10 | 563 |
| 4 |
XSS 공격 자료
| 졸리운_곰 | 2014.11.10 | 401 |
| 3 |
w2af 사용자 메뉴얼
| 졸리운_곰 | 2014.10.31 | 321 |
| 2 |
WebGoat 설치와 시작 [웹 해킹 실습]
| 졸리운_곰 | 2014.10.29 | 1647 |
| 1 |
GUI for sqlmap
| 졸리운_곰 | 2014.10.08 | 294 |

