Advisory Details

December 15th, 2013

Ecava IntegraXor Project Directory Information Disclosure Vulnerability

ZDI-13-277
ZDI-CAN-1988

CVE ID
CVSS SCORE 7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P
AFFECTED VENDORS Ecava
AFFECTED PRODUCTS IntegraXor
VULNERABILITY DETAILS


This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Ecava IntegraXor. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the storing of credentials in cleartext. The issue lies in the ability to bypass file access restrictions. This can be used along with the automatic creation of backup files, which are created whenever changes are made to a project. By abusing this flaw an attacker can disclose credentials and possibly leverage this situation to achieve remote code execution.

ADDITIONAL DETAILS
DISCLOSURE TIMELINE
  • 2013-11-06 - Vulnerability reported to vendor
  • 2013-12-15 - Coordinated public release of advisory
CREDIT Alphazorx aka technically.screwed
BACK TO ADVISORIES