103
HotOpenTickets privilege escalation
CGI
2004/03/23
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/14
2.0
Corrected the plugin structure and added the accuracy values in 1.2. Improved the pattern matching and introduced the plugin changelog in 2.0
tcp
80
open|send GET /login.php HTTP/1.0\n\n|sleep|close|pattern_exists HTTP/#.# ### *hot_*
87
This plugin was written with the ATK Attack Editor.
HotOpenTickets before 02272004_ver2c
HotOpenTickets after 02272004_ver2c
Configuration
The remote host is running HotOpenTickers, a web-based ticketing system. A vulnerability has been disclosed in all versions of this software, up to version 02272004_ver2c (not included) which may allow an attacker escalate privileges on this server.
Upgrade to Hot Open Tickets 02272004_ver2c and limit unwanted connections and communications with firewalling.
1 hour
Yes
http://www.securityfocus.com/bid/9790/exploit/
Yes
Yes
Medium
6
6
8
6
Medium
Nessus is able to do the same check.
9790
12089
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.computec.ch