Sense of Security is one of Australia’s most trusted providers of cyber resilience, information security and risk management services.

Latest announcements
© Copyright Sense of Security

Security Advisory – SOS-10-004 -Elcom Technology’s CommunityManager.NET Auth Bypass Vulnerability

Release Date: 20-Dec-2010

Last Update:

Vendor Notification Date: 20-Jan-2010

Product: Elcom Technology’s CommunityManager.NET

Platform: IIS with ASP.NET

Affected versions: CommunityManager.NET v6.7 verified and possibly others

Severity Rating: High

Impact: Application “System” user access

Attack Vector: Remote without authentication

Solution Status: Vendor patch

CVE reference: Not yet assigned

Details

The web application uses cookie parameters passed via HTTP requests to identify which user is logged in. Authentication routines can be bypassed by simply appending the below POC string to a cookie which already contains a valid ASP.NET session ID. The value given to the various cookie parameters indicates the specific user ID for the application user the attacker wishes to impersonate.

Please refer to the PDF version of this advisory  for proof of concept code examples.

Solution

Sense of Security has been advised that Elcom Technology has patched all versions of CommunityManager.NET and notified all clients.

Discovered By

Sense of Security Labs.

Our expert consultants are here to help you. For all your Cyber Security needs please contact us today.

No Comments

Sorry, the comment form is closed at this time.