[PersianHacker.NET 200503-11]Ublog reload 1.0.4 and prior Multiple Vulnerbilities

From: PersianHacker Team (pi3ch_at_yahoo.com)
Date: 03/29/05

  • Next message: Paul J Docherty: "Portcullis Security Advisory 05-011 ACPI 1.6 BIOS"
    Date: 29 Mar 2005 13:15:12 -0000
    To: bugtraq@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    [PersianHacker.NET 200503-11]Ublog reload 1.0.4 and prior Multiple Vulnerbilities
    Date: 2005 03
    Bug Number: 11

    Ublog
    Ublog reload is a complete ASP weblog system.
    More info @:
    http://www.uapplication.com

    Discussion:
    --------------------
    What are the bugs ?
    1) Cross-Site Scripting that lets attackers can inject HTML or Script.
    2) Default Database Name.

    Description bugs
    1)
    Input passed to the "msg" parameter in "login.asp" isn't properly sanitised before being returned to the user.
    Example :
    2)
    The problem is that the database file "mdb-database/ublogreload.mdb" is located inside the web root. so attackers can download it and disclose user/password of admin.
    attention : the admin's password is in the hash formating.

    Exploit:
    --------------------
    http://www.example.com/login.asp?msg=<script>alert(XSS)</script>
    http://www.example.com/mdb-database/ublogreload.mdb

    Solution:
    --------------------
    Upgrade to ublog reaload version 1.0.5

    Credit:
    --------------------
    Discovered by PersianHacker.NET Security Team
    by 3nitro (3nitro [AT] persianhacker [DOT] net)
    http://www.PersianHacker.NET

    Special Thanks: Pi3cH

    Help
    --------------------
    visit: http://www.PersianHacker.NET
    or mail me @: 3nitro [AT] persianhacker [DOT] net

    Note
    --------------------
    scripts authors contacted for this bug.


  • Next message: Paul J Docherty: "Portcullis Security Advisory 05-011 ACPI 1.6 BIOS"

    Relevant Pages

    • Addendum Re: Internet Explorer Pop-Up OBJECT Tag Bug
      ... adding an addendum about the bug which Dave ... able to control the execution of software). ... Download unsigned Activex controls - Disable ... Safe for Scripting - Disable ...
      (Bugtraq)
    • Re: *Notifying a regional settings bug* Re: Some News from Microsoft
      ... I'll check into this and try and reproduce the bug and then see what exactly ... > Hi Steve, ... when really there's just a flaw in the beta. ... so now you can go back and have lots of fun scripting. ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress.stationery)
    • Re: patch download for ME
      ... > but doesn't the same bug exist in all of these releases? ... Why not give us the patch now ... Microsoft MVP Scripting and WMI, ...
      (microsoft.public.security)
    • Re: Windows XP Service Pack 2
      ... It takes a *very* serious and wide spread problem to make Microsoft ... change a service pack. ... bug is SP6 for NT 4.0, where a bug in the Winsock interface was ... -- torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway Administration scripting examples and an ONLINE version of the 1328 page Scripting Guide: ...
      (microsoft.public.windowsxp.security_admin)
    • Re: findstr bug on XP
      ... the one reply to the posting did not indicate a solution. ... > Can anyone verify if this is an XP bug and whether there is a fix for it? ... On WinXP Pro Sp1, I get the same error as above. ... Administration scripting examples and an ONLINE version of the 1328 page Scripting Guide: ...
      (microsoft.public.windowsxp.general)