eFront "courses_ID" Path Disclosure Weakness

by Carol~ Moderator - 4/27/12 4:09 PM

In Reply to: VULNERABILITIES / FIXES - April 27, 2012 by Carol~ Moderator

Release Date : 2012-04-27

Criticality level : Not critical
Impact : Exposure of system information
Where : From remote
Solution Status : Unpatched

Software: eFront 3.x

Description:
Haunt IT has discovered a weakness in eFront, which can be exploited by malicious people to disclose certain system information.

The weakness is caused due to the application disclosing the full installation path within an error message when accessing a certain invalid "courses_ID" via the lesson information.

The weakness is confirmed in version 3.6.11 build 15059. Other versions may also be affected.

Solution:
Edit the source code to ensure that no installation path is disclosed.

Provided and/or discovered by:
Haunt IT

Original Advisory:
http://hauntit.blogspot.com/2012/04/en-efront-3610-cms-information.html

http://secunia.com/advisories/49003/