what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

HYA-2005-008-alstrasoft-epay-pro.txt

HYA-2005-008-alstrasoft-epay-pro.txt
Posted Sep 22, 2005
Authored by GeMe-GeMeS | Site h4cky0u.org

Alstrasoft Epay Pro versions 2.0 and below suffer from a directory traversal vulnerability. Exploitation details provided.

tags | exploit
SHA-256 | c750901229e42af7fda79c40bb063a109c9fb0152e9e851df5b6334e636f9510

HYA-2005-008-alstrasoft-epay-pro.txt

Change Mirror Download
------------------------------------------------------
HYA-2005-008 h4cky0u.org Advisory 008
------------------------------------------------------
Date - Mon Sep 19 2005


TITLE:
======

Alstrasoft Epay Pro 2.0 and prior Directory Traversal Vulnerability


SEVERITY:
=========

Medium


SOFTWARE:
=========

Alstrasoft EPay Pro v2.0 and prior


INFO:
=====

EPay Pro is the ultimate software solution for those who wish to run their own Paypal, Stormpay, or e-gold type of online business. Epay Pro comes with a ready out of the box website with all the features you need to run your own payment gateway system.

Support Website : https://www.alstrasoft.com/epay.htm


BUG DESCRIPTION:
================

EPay Pro version 2.0 and prior are vulnerable caused by an improper validation of user-supplied input. A remote attacker could embed in the index.php etc/passwd containing embedded code in the payment or send parameter which, once the link is clicked, would be executed to see passwords within the security context of the hosting server. An attacker could use this vulnerability to see all the victim's password authentication credentials.


POC:
====

Here is an example:

https://targeturl/index.php?read=../../../../../../../../../../../../../../etc/passwd


VENDOR STATUS:
==============

Vendor has been contacted but no response recieved till date.


FIX:
====

No fix available as of date.


CREDITS:
========

This vulnerability was discovered and researched by
GeMe-GeMeS of h4cky0u Security Forums.


mail : GeMeGeMeS at Gmail.Com

web : https://www.h4cky0u.org


ORIGINAL ADVISORY:
==================

https://www.h4cky0u.org/advisories/HYA-2005-008-alstrasoft-epay-pro.txt
Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close