SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

BugTracker.net 3.4.3 SQL Injection


Arrow  SecurityAlert : 7717
Arrow  CVE : CVE-2010-3188
Arrow  CWE : CWE-89
Arrow  SecurityRisk : High  Security Risk High  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Victim interaction required : No
Arrow  Exploit Available : Yes
Arrow  Credit : Mark van Tilburg
Arrow  Published : 01.09.2010

Arrow  Affected Software : ifdefined:bugtracker.net:3.4.3 and previous versions
ifdefined:bugtracker.net:3.4.2
ifdefined:bugtracker.net:3.4.1
ifdefined:bugtracker.net:3.4.0
i2000fdefined:bugtracker.net:3.3.9
ifdefined:bugtracker.net:3.2.0
ifdefined:bugtracker.net:3.1.9
ifdefined:bugtracker.net:3.1.8
ifdefined:bugtracker.net:3.1.7
ifdefined:bugtracker.net:3.1.6
ifdefined:bugtracker.net:3.1.5
ifdefined:bugtracker.net:3.1.4
ifdefined:bugtracker.net:3.1.3
ifdefined:bugtracker.net:3.1.2
ifdefined:bugtracker.net:3.1.1
ifdefined:bugtracker.net:3.1.0
ifdefined:bugtracker.net:3.0.9
ifdefined:bugtracker.net:3.0.8
ifdefined:bugtracker.net:3.0.7
ifdefined:bugtracker.net:3.0.6
ifdefined:bugtracker.net:3.0.5
ifdefined:bugtracker.net:3.0.4
ifdefined:bugtracker.net:3.0.3
ifdefined:bugtracker.net:3.0.1
ifdefined:bugtracker.net:3.0.0
ifdefined:bugtracker.net:2.9.9
ifdefined:bugtracker.net:2.9.8
ifdefined:bugtracker.net:2.9.7
ifdefined:bugtracker.net:2.9.6
ifdefined:bugtracker.net:2.9.5
ifdefined:bugtracker.net:2.9.4
ifdefined:bugtracke17far.net:2.9.3
ifdefined:bugtracker.net:2.9.2
ifdefined:bugtracker.net:2.9.1
ifdefined:bugtracker.net:2.9.0



Arrow  Advisory Content :  

BugTracker.net 3.4.3 SQL Injection

Name BugTracker.NET
Vendor http://www.ifdefined.com/www/
Versions Affected < 3.4.4 (when custom fields are used)

Author Mark van Tilburg
Website http://markvt.info
Contact markvantilburg [at] gmail [dot] com
Date 2010-08-22

X. INDEX

I. ABOUT THE APPLICATION
II. DESCRIPTION
III. ANALYSIS
IV. SAMPLE CODE
V. FIX
VI. Dates

I. ABOUT THE APPLICATION
________________________

A web-based bug or issue tracker written using ASP.NET,
C#, and SQL Server (SQL Server Express too).
Probably has all the features you need. Easy to setup.
Power and flexibility when you need it. Learn more at
http://ifdefined.com/bugtrackernet.html

II. DESCRIPTION
_______________

A parameter is not properly sanitised before being
used in SQL queries.

If no custom fields are used this vulnerability
cannot be misused.

III. ANALYSIS
_____________

Summary:

A) SQL Injection
_______________________________

The application allows the use of Custom Fields, searching
of these custom fields is possible on the search page.
The value used for searching the custom field is not
properly cleaned before being used in the SQL query.

Please note this vulnerability is in the code lot for a long time
if using BugTracker.NET publicly you could be vulnerable.

IV. SAMPLE CODE
_______________

Use ' in the search box of a custom field

V. FIX
______

A) Don't use custom fields

B) Upgrade to v3.4.4 (http://sourceforge.net/projects/btnet/files/)

C) Or do the fix manually by following the steps at:
http://btnet.svn.sourceforge.net/viewvc/btnet/www/search.aspx?r1=559&r2=
566

VI. DATES
______
Reported to author: 2010-08-20
Acknowledge by author: 2010-08-20
Fixed by author: 2010-08-22



Arrow  References :

http://xforce.iss.net/xforce/xfdb/61434
http://www.securityfocus.com/archive/1/archive/1/513385/100/0/threaded
http://sourceforge.net/projects/btnet/files/btnet_3_4_4_release_notes.txt/view
http://secunia.com/advisories/41150




Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.