Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-disclosure] SEC Consult SA-20051223-1 :: File Disclosure using df_next_page parameter in OracleAS Discussion Forum Portlet |
|---|---|
| Date: | Fri, 23 Dec 2005 09:23:22 +0100 |
SEC Consult Security Advisory < 20051223-1 >
========================================================================
title: < File Disclosure using df_next_page parameter
in OracleAS Discussion Forum Portlet >
program: < OracleAS Discussion Forum Portlet >
vulnerable version: < Version of May 2005 >
homepage: < http://www.oracle.com >
found: < 2005-09-16 >
by: < Johannes Greil > SEC-CONSULT / www.sec-consult.com
========================================================================
vendor description:
-------------------
Oracle's business is information - how to manage it, use it, share it,
protect it. For nearly three decades, Oracle, the world's largest
enterprise software company, has provided the software and services
that let organizations get the most up-to-date and accurate information
from their business systems.
[www.oracle.com]
vulnerability overview:
-----------------------
It is possible to read arbitrary files of the system such as the
WEB-INF directory through the discussion forum portlet. An attacker
needs to know the file names.
proof of concept:
-----------------
By requesting the forum URL and adding a null character "%00" to the
"df_next_page" parameter, it is possible to retrieve the source code of
the JSP files or other content on the server.
e.g.
$ GET
http://$host/portal/page?_pageid=XXX,XXX&_dad=portal&_schema=PORTAL&
df_next_page=htdocs/search.jsp%00
vulnerable versions:
--------------------
Version of May 2005
http://www.oracle.com/technology/products/ias/portal/point_downloads.html#forum
vendor status:
--------------
vendor notified: 2005-09-26
vendor response: 2005-09-27
patch available: -
The first response from Oracle was on 27th September (assigning bug
numbers) with a more detailed answer on 28th September. They explicitly
said that the forum is sample code and shouldn't be used in a production
environment although it can be found in such installations.
The last email from Oracle was on 21st October saying that they will fix
it "hopefully within the next 4 weeks". Asking them for a status update
at the beginning of December and another email on 19th December didn't
trigger any responses hence this advisory is being released.
solution:
---------
Only use the forum portlet in test installations and not in a production
environment.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
< Johannes Greil > / www.sec-consult.com /
SGT ::: < tke, mei, bmu, dfa > :::
smime.p7s
Description: S/MIME Cryptographic Signature
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-disclosure] SEC Consult SA-20051223-0 :: Multiple Cross Site Scripting Vulnerabilities in OracleAS Discussion Forum Portlet, Johannes Greil |
|---|---|
| Next by Date: | [Full-disclosure] [ GLSA 200512-13 ] Dropbear: Privilege escalation, Stefan Cornelius |
| Previous by Thread: | [Full-disclosure] SEC Consult SA-20051223-0 :: Multiple Cross Site Scripting Vulnerabilities in OracleAS Discussion Forum Portlet, Johannes Greil |
| Next by Thread: | [Full-disclosure] [ GLSA 200512-13 ] Dropbear: Privilege escalation, Stefan Cornelius |
| Indexes: | [Date] [Thread] [Top] [All Lists] |