[Archived content from justinsamuel.com]

Vulnerability: AWBS Dedicated Server Info Visible to All Users

Posted on June 10, 2007, 9:00 am, by justin, under Vulnerabilities.

Advisory: AWBS Dedicated Server Info Visible to All Users
Release Date: 2007-06-10
Last Modified: 2007-07-26
Author: Justin Samuel [http://www.justinsamuel.com]

Application: AWBS < 2.6.0
Severity: Less Critical
Impact: Disclosure of sensitive information
Vendor Status: Vendor released version 2.6.0 to address issue. Testing still needed to verify that issue is corrected.

Vendor: Total Online Solutions, Inc.
App. Website: http://www.awbs.com/
References: http://www.justinsamuel.com/2007/06/10/awbs-dedicated-server-info-visible-to-all-users-vulnerability/



Advanced Webhost Billing System (AWBS) allows any user access to the details of
all dedicated servers sold through AWBS.

The information made available about all dedicated servers includes:
- Server hostname
- Main IP address
- Admin username
- Nameservers


Proof of Concept:

Proof of concept exploit code has been provided to the vendor.


Disclosure Timeline:

2007-06-10: Informed AWBS developers of vulnerability details by email.

2007-07-26: Public disclosure.



If using AWBS to sell dedicated servers, remove the file smanage.php until the
vendor releases a fix or upgrade to patched version of software.