360 Web Manager 3.0 multiple defects and repair

Source: Internet
Author: User

# Exploit Title: Multiple vulnerabilities in 360 Web Manager 3.0

# Google Dork: "Powered by 360 Web Manager 3.0"

# Date: 15/04/2011

# Author: Ignacio Garrido

# Contact: Ign.sec@gmail.com

# Software Link: www.360webmanager.com

# Version: v3.0

# Tested on: Linux * 2.6.18 *

# Vulnerability description:

360 Web Manager 3.0 makes use of a panel manager which uses a simple file

Manager, this script dont require any authorization at all to upload, list,

Or even delete files.

We can find this panel at: http ://

Www.2cto.com/adm/barra/assetmanager/assetmanager.php.

By looking the source code we can find the internal path of the application

Right next to: "<input type =" hidden "name =" inpAssetBaseFolder0"

Id = "inpAssetBaseFolder0"

Value = ""

Trough a forged post we can manipulate the path of the folder to list or

Delete: inpFileToDelete = % 2 FfileToDelete % 2F & inpCurrFolder = % 2 FpathToList % 2F

Also when uploading a file we can easily change the path of the folder

Changing the "inpCurrFolder2" parameter (theres no restriction to upload

Php files !).

Possible solutions:

* Use the admin panel session to authenticate the use of the file manager.

* Forbid the upload of files with dangerous extensions such as. php,. php5,

Etc.

* Give the appropriate permissions to read files within its own file

Directory.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.