BEA Tuxedo and WebLogic企业输入验证漏洞

BEA Tuxedo and WebLogic企业输入验证漏洞

漏洞ID 1107556 漏洞类型 输入验证
发布时间 2003-10-30 更新时间 2005-10-20
图片[1]-BEA Tuxedo and WebLogic企业输入验证漏洞-安全小百科CVE编号 CVE-2003-0621
图片[2]-BEA Tuxedo and WebLogic企业输入验证漏洞-安全小百科CNNVD-ID CNNVD-200312-004
漏洞平台 CGI CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/23312
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200312-004
|漏洞详情
BEATuxedo8.1以及之前的版本的管理控制台存在漏洞。远程攻击者借助INIFILE参数的恶意路径确定Web根目录外的文件是否存在。
|漏洞EXP
source: http://www.securityfocus.com/bid/8931/info

A vulnerability has reported to exist in BEA Tuxedo and WebLogic Enterprise due to Tuxedo administration console. The script is reported to accept various initialization arguments such as INIFILE that are not properly sanitized for user-supplied input. This issue may allow an attacker to carry out attacks such as denial of service, file disclosure, and cross-site scripting.

An attacker may be able to determine the existence of a file outside the web server root by supplying passing various path values for INIFILE.

A denial of service condition could be caused in the software by providing a device name such as CON, AUX, COM1, COM2 instead of a valid file name as one of the arguments for INIFILE. This may cause the service to crash or hang.

A cross-site scripting vulnerability has also been reported to exist in the software due to insufficient santization of user-supplied input to INIFILE. This problem presents itself when an invalid file name is supplied as an argument for INIFILE. This vulnerability could be exploited to steal cookie-based credentials. Other attacks are possible as well. 

http://www.example.com/udataobj/webgui/cgi-bin/tuxadm.exe?INIFILE=<script>alert('XSS')</script>
|参考资料

来源:BID
名称:8931
链接:http://www.securityfocus.com/bid/8931
来源:BUGTRAQ
名称:20031031CorsaireSecurityAdvisory:BEATuxedoAdministrationCGImultipleargumentissues
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=106762000607681&w;=2
来源:dev2dev.bea.com
链接:http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp
来源:XF
名称:bea-tuxedo-file-disclosure(13559)
链接:http://xforce.iss.net/xforce/xfdb/13559

相关推荐: PowerTech PowerLock Input Validation Vulnerability

PowerTech PowerLock Input Validation Vulnerability 漏洞ID 1096807 漏洞类型 Input Validation Error 发布时间 2005-04-21 更新时间 2005-04-21 CVE编号 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享