Portcullis Advisory 05-006 Update, Webseries Payment Application

From: Paul J Docherty (PJD_at_portcullis-security.com)
Date: 02/02/05

  • Next message: Paul J Docherty: "Portcullis Advisory 05-007 Update, Webseries Payment Application"
    Date: Wed, 2 Feb 2005 18:09:26 -0000
    To: "bugs" <bugs@securitytracker.com>, "Bugtraq" <bugtraq@securityfocus.com>, "secunia" <vuln@secunia.com>
    
    

    Portcullis Security Advisory

    AREAS UPDATED: VENDOR RESPONSE.

    VENDOR RESPONSE:

    The product vendor, Bottomline Technologies has provided Portcullis with
    the following response to the security advisory. It should be noted that
    the resolution of this issue has not been verified by Portcullis:

    Bottomline acknowledge that there is a slight risk of exposure of data
    via unauthorised report generation. In order to further enhance the
    security of the system a service pack will be released in Q1 2005. This
    ensures the reporting module no longer passes the path and report
    information on the URL line. This information is kept on the server and
    passed using the database and additionally the report being executed is
    validated against the user entitlements.

    Contact Bottomline at: support@bottomline.co.uk Tel: +44 (0)1189
    258253.
     
    Vulnerable System:
          
    Webseries Payment Application
     
    Vulnerability Title:
     
    Directory & File Enumeration Via Reporting System
     
    Vulnerability discovery and development:
     
    Portcullis Security Testing Services
     
    Affected systems:
     
    Bottomline Webseries Payment Application
     
    Details:
     
    By manipulating the values of certain variables used during report
    selection it was possible enumerate the directory structure on the web
    server.
     
    The BTInteractiveViewer.asp script combines the values of the
    "ReportPath" and "ReportName" variables to determine the location of the
    selected report template.
     
    When a non-existent file is specified in the "ReportName" variable an
    error message of "The system cannot find the file specified" is
    returned.
     
    When a non-existent directory is specified in the "ReportPath" variable
    an error message of "The system cannot find the path specified" is
    returned.
     
    When the "ReportName" variable contains the name of a file that exists
    in the directory specified in the "ReportPath" variable an error message
    of "Unable to load report" is returned.
     
    Impact:
     
    An attacker can use the information obtained by this issue to gain a
    better understanding of the structure of the underlying Filesystem of
    the web
    server.
     
    Exploit:
     
    Exploit code not required.
     
    Copyright:
     
    Copyright (c) Portcullis Computer Security Limited 2005, All rights
    reserved worldwide. Permission is hereby granted for the electronic
    redistribution of this information. It is not to be edited or altered in
    any way without the express written consent of Portcullis Computer
    Security Limited.
     
    Disclaimer:
     
    The information herein contained may change without notice. Use of this
    information constitutes acceptance for use in an AS IS condition. There
    are NO warranties, implied or otherwise, with regard to this information
    or its use. Any use of this information is at the user's risk. In no
    event shall the author/distributor (Portcullis Computer Security
    Limited) be held liable for any damages whatsoever arising out of or in
    connection with the use or spread of this information

    *************************************************************
    The information in this email is confidential and may be
    legally privileged. It is intended solely for the addressee.
    Any opinions expressed are those of the individual and do not
    represent the opinion of the organisation.
    Access to this email by persons other than the intended
    recipient is strictly prohibited.
    If you are not the intended recipient, any disclosure, copying,
    distribution or other action taken or omitted to be taken in
    reliance on it, is prohibited and may be unlawful.
    When addressed to our clients any opinions or advice contained
    in this email is subject to the terms and conditions expressed
    in the applicable Portcullis Computer Security Limited terms
    of business.
    **************************************************************


  • Next message: Paul J Docherty: "Portcullis Advisory 05-007 Update, Webseries Payment Application"

    Relevant Pages


    Loading