what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

EV0138.txt

EV0138.txt
Posted Sep 14, 2006
Authored by Aliaksandr Hartsuyeu | Site evuln.com

NX5Linkx version 1.0 suffers from arbitrary file disclosure, multiple SQL injection, and HTTP response splitting vulnerabilities.

tags | exploit, web, arbitrary, vulnerability, sql injection
advisories | CVE-2006-4503, CVE-2006-4504, CVE-2006-4505
SHA-256 | 767ede366b554aeb6bf350b179f671e5cd739145acf7762bd05061614695ac0b

EV0138.txt

Change Mirror Download
New eVuln Advisory:
NX5Linkx Multiple Vulnerabilities
http://evuln.com/vulns/138/summary.html

--------------------Summary----------------
eVuln ID: EV0138
CVE: CVE-2006-4503 CVE-2006-4504 CVE-2006-4505
Vendor: NX5
Vendor's Web Site: http://nx5ware.nx5.org/
Software: NX5Linkx
Sowtware's Web Site: http://nx5ware.nx5.org/links.php
Versions: 1.0
Critical Level: Dangerous
Type: Multiple Vulnerabilities
Class: Remote
Status: Unpatched. No reply from developer(s)
PoC/Exploit: Available
Solution: Not Available
Discovered by: Aliaksandr Hartsuyeu (eVuln.com)

-----------------Description---------------
1. Arbitrary file disclosure Vulnerability

Vulnerable script: link.php

Parameter logo is not properly sanitized. It used as full local path to
logo filename. Script do the copy of this file in logos directory. This
directory is available from the web.
This can be used to read arbitrary files.


2. Multiple SQL Injections.

Vulnerable scripts: The name of those scripts are defined by webmaster.
First - (a) displays links list. Second - (b) "out" script which do the
redirections when someone clicks on link

Parameters c(script "a"), l(script "b") are not properly sanitized
before being used in SQL query. This can be used to make any SQL query
or make a HTTP response-splitting attack by injecting arbitrary SQL
code.

Condition: magic_quotes_gpc = off


3. HTTP Response Splitting.

Vulnerable Script: link.php

Parameter url is not properly sanitized. This can be used to make HTTP
Response Splitting attack.



--------------PoC/Exploit----------------------
Available at: http://evuln.com/vulns/138/exploit.html


1. Arbitrary file disclosure Example.

URL: http://host/link.php
Logo URL: /etc/passwd

This file can be downloaded using the link:
http://host/logos/N.
N - ID of the link


2. SQL Injection Examples.

http://host/links.php? c=999'% 20union%20select% 201,222/*
http://host/out.php? l=999' union select 1,1,'http://google.com', 1,1,1,1/*



3. HTTP Response Splitting.

URL: http://host/link.php
URL(in form): http://host.com% 0D%0A%0D%0AHTTP/1.0 200 OK%0D%0A%0D% 0A.......

--------------Solution---------------------
No Patch available.

--------------Credit-----------------------
Discovered by: Aliaksandr Hartsuyeu (eVuln.com)


Regards,
Aliaksandr Hartsuyeu
http://evuln.com - Penetration Testing Services
.

Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close