SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

HYSA-2006-003 Oi! Email Marketing 3.0 SQL Injection


Arrow  SecurityAlert : 483
Arrow  CVE : CVE-2006-0920
Arrow  SecurityRisk : Medium  Security Risk Medium  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : Yes
Arrow  Exploit Available : Yes
Arrow  Credit : h4cky0u
Arrow  Published : 24.02.2006

Arrow  Affected Software :
Oi! Email Marketing 3.0



Arrow  Advisory Content :  

------------------------------------------------------
HYSA-2006-003 h4cky0u.org Advisory 012
------------------------------------------------------
Date - Thu Feb 24 2006

TITLE:
======

Oi! Email Marketing 3.0 SQL Injection

SEVERITY:
=========

High

SOFTWARE:
=========

Oi! Email Marketing 3.0. Prior versions maybe affected

INFO:
=====

Oi Email Marketing System is a Linux compatible application that can be a
stand-alone product or can be integrated into Mambo 2002 content management
system. It uses a powerful database which resides on your webserver and
allows complete control over all your subscribers, campaigns and emails.

Support Website : www.miro.com.au

DESCRIPTION:
============

Oi Email Marketing System is prone to an SQL injection vulnerability. This
issue is due to a failure in the index.php script of the application to
properly sanitize user-supplied input before using it in SQL queries.

Successful exploitation could result in a compromise of the application,
disclosure or modification of data, or may permit an attacker to exploit
vulnerabilities in the underlying database implementation.

POC:
====

First go to http://www.site.com/oi/index.php

In this login page provide the following inputs:

Username : username' OR '

Password : ' OR '

Note : here username should be a valid user registered on the site
(generally admin)

Also, if a 'superadministrator'login is found and sucessfully exploited the
server's
ftp password can be found by clicking 'Configuration' and viewing the pages
source:

(It's hidden by *)

<TD CLASS="dialogue_heading">Password</TD>
<TD><input type="password" name="ftpPassword" value="password"></TD>

VENDOR STATUS
=============

Vendor was contacted repeatedly but no response received till date.

FIX:
====

No fix available as of date.

CREDITS:
========

- This vulnerability was discovered and researched by -

Illuminatus of h4cky0u Security Forums.

Mail : illuminatus85 at gmail dot com

Web : http://www.h4cky0u.org

- Co Researcher -

h4cky0u of h4cky0u Security Forums.

Mail : h4cky0u at gmail dot com

Web : http://www.h4cky0u.org

ORIGINAL ADVISORY:
==================

http://www.h4cky0u.org/advisories/HYSA-2006-003-oi-email.txt

--
http://www.h4cky0u.org
(In)Security at its best...





Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc:fts_*() Multiple Denial of Service

Security Risk Medium- 2009-10-02

The fts functions are provided for traversing UNIX file hierarchies...

Apache RSS Apache Alert

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion in work
   directory

» Apache Tomcat 6.0.20 and
   5.5.28 insecure partial
   deploy after failed
   undeploy

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion and/or
   alteration

PHP RSS PHP Alert

» PHP 5.2.12/5.3.1
   session.save_path
   safe_mode and
   open_basedir bypass

» PHP 5.2.12/5.3.1 Multiple
   Vulnerabilities

» PHP 5.2.11 libgd multiple
   vulnerabilities

» PHP 5.2.11 tempnam()
   safe_mode bypass

Copyright © SecurityReason.com. All Rights Reserved.