iResponz Customer Respons and Issue Management Software Arbitrary File Upload Vulnerability

Discovered by: Arif fahmi (Ryuzaki)
Vendor information:
"Responz - These days, an organization success is extremely dependent on the effectiveness of its’ Customer Service.
Our society is getting more knowledgeable and aware of their rights as a customer. Augmentation trend of unsatisfied customer complaints and reports have been observed."
Vendor URI:
Issue: iResponz Customer Respons and Issue Management bypass shell script (PHP)
The iResponz offers a feature to eliminate suspicious pattern passed to the website by a 
PHP enable.
For example, we have the following:
$ curl --head http://localhost/_attachment/10870/shell.php
HTTP/1.1 200 OK
Date: Fri, 19 Oct 2012 15:10:53 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-Powered-By: PHP/5.3.3
Content-type: text/html
Content-Length: 0
Let's try it Register > go to TAMBAH LAMPIRAN > and UPLOAD

Vulnerability Code:

<cfif IsDefined("form.newattach")>
<cfif form.FiletoUpload IS "">
<cflocation url="eaduan_detail.cfm?keyid=#url.keyid#&attach=TRUE&fault=1" addtoken="yes">

<cfif NOT DirectoryExists("#application.attachpath#\#url.keyid#\")>
<cfdirectory action="Create" directory="#application.attachpath#\#url.keyid#\">
<cfcatch type = "any">
  <cflocation url="eaduan_detail.cfm?keyid=#url.keyid#&attach=TRUE&fault=2" addtoken="yes">

The CFM won't be executed in PHP but bypass with file like l.php.jpeg / l.php;.jpeg / l.php;.pjpeg / l.php.gif.

and more in google
Dork: iresponz
Just disable PHP :) Thank for Adnan Shukor (./xanda).

