Writer's Block SQL Injection Vulnerabilities

2008.04.11
Credit: katharsis
Risk: Medium
Local: No
Remote: Yes
CWE: CWE-89


CVSS Base Score: 7.5/10
Impact Subscore: 6.4/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: Partial
Integrity impact: Partial
Availability impact: Partial

[>>] Writer?s Block SQL Injection Vulnerabilities [<<] [x] Vendor Information "If the written word is the wheel, then Writer?s Block is the sweet, sweet fossil fuel in the engine that keeps it spinning. A free, flexible, elegant Content Management System that helps you maintain any web site you want, at any size you want, with no hassle and no restrictions. In fact, it?s running this entire site right now." http://www.desiquintans.com [x] Attack Information The variable "PostID" can be filled with malicious content to execute SQL code: ---- permalink.php, line 212: $getpost = @mysql_query("SELECT Title, Timestamp, Body, PostCat1, PostCat2, PostCat3, PostCat4, Author FROM ".POSTS_TBL." WHERE PostID='".$_GET['PostID']."' AND Draft=0"); ---- permalink.php, line 298: $prevlink = mysql_query("SELECT PostID FROM ".POSTS_TBL." WHERE PostID<".$_GET['PostID']." AND Draft=0 ORDER BY Timestamp DESC LIMIT 1"); ---- permalink.php, line 304: $nextlink = mysql_query("SELECT PostID FROM ".POSTS_TBL." WHERE PostID>".$_GET['PostID']." AND Draft=0 ORDER BY Timestamp ASC LIMIT 1"); ---- [x] Exploit The issue can be exploited through a web browser. [x] Patch Just add an intval(): ---- permalink.php, line 212: $getpost = @mysql_query("SELECT Title, Timestamp, Body, PostCat1, PostCat2, PostCat3, PostCat4, Author FROM ".POSTS_TBL." WHERE PostID='".intval($_GET['PostID'])."' AND Draft=0"); ---- permalink.php, line 298: $prevlink = mysql_query("SELECT PostID FROM ".POSTS_TBL." WHERE PostID<".intval($_GET['PostID'])." AND Draft=0 ORDER BY Timestamp DESC LIMIT 1"); ---- permalink.php, line 304: $nextlink = mysql_query("SELECT PostID FROM ".POSTS_TBL." WHERE PostID>".intval($_GET['PostID'])." AND Draft=0 ORDER BY Timestamp ASC LIMIT 1"); ---- [x] Credits The vulnerability has been discovered by katharsis - www.katharsis.x2.to


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top