[UNIX] AZBB Multiple Vulnerabilities

SecuriTeam <[email protected]>
Newsgroups gmane.comp.security.securiteam
Message-ID <[email protected]>
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html 

- - - - - - - - -



  AZBB Multiple Vulnerabilities
------------------------------------------------------------------------


SUMMARY

 <http://azbb.cyaccess.com/> AZbb is "a forum that was written with a 
primary focus on security. AZbb does not require a database such as MySQL, 
PostgreSQL or MSSQL and can even be used as a blog, or a portal".

File Inclusion, Arbitrary File Deletion and File Enumeration 
vulnerabilities have been discovered in AZbb.

DETAILS

Vulnerable Systems:
 * AZBB version 1.0.07d and prior

Immune Systems:
 * AZBB version 1.0.08

File Inclusion:
There is a file inclusion vulnerability in AZBB 1.0.07a - 1.0.07c that is 
the result of missing code that is present in all of the  other AZBB 
versions. This file inclusion issue poses a different  risk level 
depending on your server configuration.
Lets have a  look at the code (main_index.php):

########## Get the Abstraction Layer
$inc = $dir_src.'/'.$abs_layer.'_db_ops.php';
file_exists($inc) ? include($inc) : exit('Unable to open '.$inc);

Since the "AZBB KEY CHECK" that exists in other pages is missing  from 
this page we can influence both the $dir_src and $abs_layer  variables if  
register globals is on. However, what we can do with  this greatly depends 
on the server configuration, and this is a   result of the file_exists() 
function being used. You can read  more about this in the official php 
manual located  <http://us2.php.net/file_exists> here.

Arbitrary File Deletion:
There is an issue in AZBB that could allow for an attacker logged in as an 
administrative, or a malicious administrative to delete arbitrary files 
outside the scope of the application. The vulnerable code is in 
admin_avatar.php and admin_attachment.php. Lets have a look at the code in 
admin_avatar.php

## trim all and delete
foreach ($_POST['avat_select'] as $ent)
{
        if (file_exists($dir_avatar.'/'.$ent))
        { unlink($dir_avatar.'/'.$ent); }
}

As we can see there are no checks made for traversal sequences, and a user 
with administrative privileges could easily delete arbitrary files on the 
server. The vulnerability in admin_attachment.php is nearly identical.

Arbitrary File Enumeration:
There is an issue in AZBB that can be exploited by both users and guests 
alike to tell whether or not files on the target server exists. This is 
due to a file check coming before the input is cleaned in attachment.php:
elseif (!file_exists($dir_att.'/'.$_POST['attachment'])) {$error =
$txt_err[13];}

This issue can not be used to download arbitrary files, because the input 
is cleaned before the file is included, but we can enumerate files. To 
check if a file extension the target web server all an attacker has to do 
is modify the "attachment" parameter to include traversal sequences. If 
the file exists we will be prompted with a download, and if it doesn't 
exists we will see an error message.

Patch Availability:
The developer of AZBB was very quick to respond and has addressed these 
issues. A complete change log can be seen by following the URL posted 
below. Also, you will find the link to the updated AZBB 1.0.08 downloads 
below:
 <http://azbb.cyaccess.com/azbb.php?1091778548> 
http://azbb.cyaccess.com/azbb.php?1091778548
 <http://azbb.cyaccess.com/azbb.php?1091872271> 
http://azbb.cyaccess.com/azbb.php?1091872271


ADDITIONAL INFORMATION

The information has been provided by  <mailto:[email protected]> 
GulfTech Security Research.
The original article can be found at:  
<http://www.gulftech.org/?node=research&article_id=00068-04192005> 
http://www.gulftech.org/?node=research&article_id=00068-04192005



======================================== 


This bulletin is sent to members of the SecuriTeam mailing list. 
To unsubscribe from the list, send mail with an empty subject line and body to: [email protected] 
In order to subscribe to the mailing list, simply forward this email to: [email protected] 


==================== 
==================== 

DISCLAIMER: 
The information in this bulletin is provided "AS IS" without warranty of any kind. 
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.