Full Disclosure mailing list archives

Scrumworks Pro authenticated arbitrary password reset


From: Brandon Perry <bperry.volatile () gmail com>
Date: Thu, 5 Jun 2014 09:59:39 -0500

The latest available version of Scrumworks Pro does not perform proper
authorization checks when users attempt to change passwords via the Java
Web Start client.

If you capture the request the web start client makes when changing the
'administrator' user's password, and substitute the JSESSIONID cookie with
that of another, lesser privileged authenticated user's JSESSIONID cookie,
making the request will still result in the administrator user's password
to be changed.

I hope to have a Metasploit module available this evening.

-- 
http://volatile-minds.blogspot.com -- blog
http://www.volatileminds.net -- website

_______________________________________________
Sent through the Full Disclosure mailing list
http://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/


Current thread: