DNSTools验证可绕过漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1106710 漏洞类型 未知
发布时间 2002-04-28 更新时间 2005-05-02
CVE编号 CVE-2002-0613 CNNVD-ID CNNVD-200206-007
漏洞平台 PHP CVSS评分 10.0
|漏洞来源
https://www.exploit-db.com/exploits/21425
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200206-007
|漏洞详情
DNSTools是一款基于WEB的DNS信息管理工具,由PHP语言实现,并可使用在Linux和Solaris操作系统下。DNSTools验证处理中存在漏洞,可导致远程攻击者绕过验证机制以管理员权限访问系统。DNSTools使用两个变量来保存用户验证状态(普通用户/管理员),由于程序对这两个变量数据缺少正确充分的检查,攻击者可以简单的在URL中增加"user_logged_in=true"和管理员权限变量"user_dnstools_administrator=YES",就能以管理员权限访问DNSTools系统。
|漏洞EXP
source: http://www.securityfocus.com/bid/4617/info

DNSTools is a web based managment tool for DNS information. It is implemented in PHP, and available for Linux and Solaris.

A vulnerability has been reported in some versions of DNSTools which allows any remote attacker to gain administrative access. An artificially constructed URL may define variables used to track user authentication and administrative access. 

http://www.example.com/dnstools.php?section=hosts&user_logged_in=true
http://www.example.com/dnstools.php?section=security&user_logged_in=true&user_dnstools_administrator=YES
|参考资料

来源:BID
名称:4617
链接:http://www.securityfocus.com/bid/4617
来源:XF
名称:dnstools-auth-bypass(8948)
链接:http://www.iss.net/security_center/static/8948.php
来源:BUGTRAQ
名称:20020428dnstools:authenticationbypassvulnerability
链接:http://archives.neohapsis.com/archives/bugtraq/2002-04/0390.html
来源:www.dnstools.com
链接:http://www.dnstools.com/dnstools_2.0.1.tar.gz