Webshop Hun 1.062S Directory Traversal

2015.03.05
Credit: Wang Jing
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-22

*Webshop hun v1.062S Directory Traversal Security Vulnerabilities* Exploit Title: Webshop hun v1.062S /index.php &mappa Parameter Directory Traversal Security Vulnerabilities Product: Webshop hun Vendor: Webshop hun Vulnerable Versions: v1.062S Tested Version: v1.062S Advisory Publication: Mar 04, 2015 Latest Update: Mar 04, 2015 Vulnerability Type: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] CVE Reference: * Credit: Wang Jing [CCRG, Nanyang Technological University (NTU), Singapore] *Advisory Details:* *(1) Vendor & Product Description:* *Vendor:* Webshop hun *Product & Version:* Webshop hun v1.062S *Vendor URL & Download:* Webshop hun can be downloaded from here, http://www.webshophun.hu/index *Product Introduction:* Webshop hun is an online product sell web application system. "If our webshop you want to distribute your products, but it is too expensive to find on the internet found solutions, select the Webshop Hun shop program and get web store for free and total maker banner must display at the bottom of the page 468x60 size. The download shop program, there is no product piece limit nor any quantitative restrictions, can be used immediately after installation video which we provide assistance. "The Hun Shop store for a free for all. In our experience, the most dynamic web solutions ranging from our country. If the Webshop Hun own image does not suit you, you can also customize the look of some of the images and the corresponding text replacement, or an extra charge we can realize your ideas. The Webshop Hun pages search engine optimized. They made the Hun Shop web program to meet efficiency guidelines for the search engines. The pages are easy to read and contain no unnecessary HTML tags. Any web page is simply a few clicks away." *(2) Vulnerability Details:* Webshop hun has a web application security bug problem. It can be exploited by Directory Traversal (Arbitrary - Remote & Local File Include ( RFI & LFI)) attacks. *(2.1) *The vulnerability occurs at "index.php?" page with "&mappa" parameter. *References:* http://tetraph.com/security/directory-traversal-vulnerability/webshop-hun-v1-062s-directory-traversal-security-vulnerabilities/ http://securityrelated.blogspot.com/2015/03/webshop-hun-v1062s-directory-traversal.html http://www.inzeed.com/kaleidoscope/computer-web-security/webshop-hun-v1-062s-directory-traversal-security-vulnerabilities/ http://diebiyi.com/articles/%E5%AE%89%E5%85%A8/webshop-hun-v1-062s-directory-traversal-security-vulnerabilities/ https://itinfotechnology.wordpress.com/2015/03/04/webshop-hun-v1-062s-directory-traversal-security-vulnerabilities/ http://lists.kde.org/?a=139222176300014&r=1&w=2 -- Wang Jing, Division of Mathematical Sciences (MAS), School of Physical and Mathematical Sciences (SPMS), Nanyang Technological University (NTU), Singapore. http://www.tetraph.com/wangjing/ https://plus.google.com/u/0/+JingWang-tetraph-justqdjing/posts

References:

http://tetraph.com/security/directory-traversal-vulnerability/webshop-hun-v1-062s-directory-traversal-security-vulnerabilities/
http://securityrelated.blogspot.com/2015/03/webshop-hun-v1062s-directory-traversal.html
http://www.inzeed.com/kaleidoscope/computer-web-security/webshop-hun-v1-062s-directory-traversal-security-vulnerabilities/
http://diebiyi.com/articles/%E5%AE%89%E5%85%A8/webshop-hun-v1-062s-directory-traversal-security-vulnerabilities/
https://itinfotechnology.wordpress.com/2015/03/04/webshop-hun-v1-062s-directory-traversal-security-vulnerabilities/
http://lists.kde.org/?a=139222176300014&r=1&w=2


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2017, cxsecurity.com

 

Back to Top