SpareNet Servers Advertising & Link Exchange

اطلاعیه

بستن
هیچ اطلاعیه ای هنوز ایجاد نشده است .

Joomla com_fireboard - SQL Injection Vulnerability

بستن
X
 
  • فیلتر
  • زمان
  • نمایش
پاک کردن همه
نوشته‌های جدید

  • Joomla com_fireboard - SQL Injection Vulnerability

    [align=LEFT]

    [php]

    Title:
    ======
    Joomla com_fireboard - SQL Injection Vulnerability


    Date:
    =====
    2012-07-11


    References:
    ===========
    http://www.vulnerability-lab.com/get_content.php?id=655


    VL-ID:
    =====
    655


    Common Vulnerability Scoring System:
    ====================================
    7.3


    Introduction:
    =============
    Joomla is a free and open source content management system (CMS) for publishing content on the World
    Wide Web and intranets and a model–view–controller (MVC) Web application framework that can also be
    used independently.

    Joomla is written in PHP, uses object-oriented programming (OOP) techniques and software design
    patterns, stores data in a MySQL database, and includes features such as page caching,
    RSS feeds, printable versions of pages, news flashes, blogs, polls, search, and support for language
    internationalization.

    Joomla had been downloaded 23 million times. Between March 2007 and February 2011 there had been
    more than 21 million downloads. As of November 2011, there are over 8,600 free and commercial
    extensions available from the official Joomla! Extension Directory and more available from other sources.

    (Copy of the Vendor Homepage: http://en.wikipedia.org/wiki/Joomla)


    Abstract:
    =========
    The Laboratory Researcher (Nafsh) Ehram Shahmohamadi (sec-lab.ir) discovered a SQL Injection Vulnerability in
    the com_fireboard module of the joomla CMS.


    Report-Timeline:
    ================
    2012-07-11: Public or Non-Public Disclosure


    Status:
    ========
    Published


    Exploitation-Technique:
    =======================
    Remote


    Severity:
    =========
    High


    Details:
    ========
    A SQL Injection vulnerability is detected in the com_fireboard module of the joomla Content Management System.
    Remote attackers & low privileged user accounts can execute/inject own sql commands to compromise the application dbms.
    The vulnerability is located in the com_fireboard module with the bound vulnerable func fb_ parameter.
    Successful exploitation of the vulnerability result in dbms (Server) or application (Web) compromise.

    Vulnerable Module(s):
    [+] index.php?option=com_fireboard

    Vulnerable Parameter(s):
    [+] func fb_


    Proof of Concept:
    =================
    The sql injection vulnerability can be exploited by remote attackers without user inter action & with low
    privileged user account. For demonstration or reproduce ...

    Dork(s):
    inurl:"id=" & intext:"/com_fireboard/"

    PoC:
    http://[TARGET]/index.php?option=com_fireboard&Itemid=0&id=1&catid =0&func=fb_pdf'[SQL-INJECTION]

    Reference(s):
    xxx.com/index.php?option=com_fireboard&Itemid=0&id=1&catid =5&func=fb_pdf'[SQL-INJECTION]
    xxx.com/2012/index.php?option=com_fireboard&Itemid=79&id=1&cati d=2&func=fb_pdf'[SQL-INJECTION]
    xxx.com/fireboard/index.php?option=com_fireboard&Itemid=38&id=22111& catid=16&func=fb_pdf'[SQL-INJECTION]
    xxx.com/board/index.php?option=com_fireboard&Itemid=54&id=70122& catid=12&func=fb_pdf'[SQL-INJECTION]
    xxx.com/jmfireboard/index.php?option=com_fireboard&Itemid=54&id=70122& catid=12&func=fb_pdf'[SQL-INJECTION]

    [/php][/align]
    [align=center][/align]

  • #2
    RE: Joomla com_fireboard - SQL Injection Vulnerability

    سلام
    میشه یک دورک هم قرار بدید




    ممنون

    نظر


    • #3
      RE: Joomla com_fireboard - SQL Injection Vulnerability

      inurl:index.php?option=com_fireboard
      [align=center][/align]

      نظر

      صبر کنید ..
      X