Fusen News 3.3 Account Add Vulnerability

From: DarkKnight (mbuzz04at_private)
Date: Thu Aug 14 2003 - 22:28:49 PDT

  • Next message: Peter Busser: "Re: Buffer overflow prevention"

    
     ('binary' encoding is not supported, stored as-is)
    Author: DarkKnight
    My site: http://www.insecureonline.com
    Product: Fusen News 3.3 (maybe lower)
    Side Note: This vulnerability is for an OLD VERSION of Fusen News. The 
    only reason I'm posting this is because I still see people using Fusen 
    News 3.3.
    Vendors: Not contacted (Upgrade available with fix)
    
    A vulnerability exists in Fusen News 3.3 that allows attackers to add 
    accounts with admin or normal privlidges. If an account is added, the 
    attacker will be able to modify news, post news, delete/add accounts, 
    etc. When adding accounts, Fusen News 3.3 does not perform a login check, 
    allowing anyone to add accounts through a direct URL.
    
    A sample is listed below
    
    http://www.website.com/FusenNews/?
    id=signup&username=DarkKnight&email=EMAILat_private+&password=123456&icon=
    &le=3
    
    The above URL would add the account "DarkKnight" with the 
    password "123456" and the email "EMAILat_private" with Administrator 
    abilities to the account list.
    
    The vendor has already made upgrades for Fusen News 3.3 so to fix the 
    vulnerability just upgrade. Besides, Fusen News 3.6 looks hot.
    
    The two people who deserve credit for this vulnerability are: Fusen and 
    DarkKnight [me :)]
    
    Want great hosting? Get it at http://www.onlinehoster.com
    



    This archive was generated by hypermail 2b30 : Fri Aug 15 2003 - 09:59:43 PDT