The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


PhpWebFTP 3.2 Login Script


<< Previous INDEX Search src / Print Next >>
Date: 17 Apr 2006 02:21:52 -0000
From: [email protected]
To: [email protected]
Subject: PhpWebFTP 3.2    Login Script
X-Virus-Scanned: antivirus-gw at tyumen.ru


Summary 

phpWebFTP enables connections to FTP servers, even behind a firewall not allowing traffic. phpWebFTP bypasses the firewall by making a FTP connection from your webserver to the FTP server and transfering the files to your webclient over the http protocol
Issue : Well I have found that most of the sites that use phpwebftp v3.2 > less have a problem. The user login script is a javascript file called script.js. This file validates the user input in the logon box. But to my surprise this file is directly accessed by web browser . The disclosure of the source code can help an attacker to trigger code injections . Exploit : http://www.anysite.com/PhpWebFtp/include/script.js Further a directory traversal is possible via malicious arguments passed on the web browser using POST Method relative to the path of phpWebftp ie. http://www.anysite.com/PhpWebFtp/index.php? . 'server=1&port=21&goPassive=on&user=1&password=1&language=../../../../../../../../etc/passwd%00'

<< Previous INDEX Search src / Print Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру