|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Roundcube Webmail |
|
Posted: Fri Jul 27, 2007 6:05 am |
|
|
zer0-c00l |
Advanced user |
|
|
Joined: Jun 25, 2004 |
Posts: 72 |
Location: BRAZIL! |
|
|
|
|
|
|
I'm trying to discover some vulnerabilities in Roundcube Webmail, but i'm not good in search holes in php files
Searching in the PHPs, i found these lines, which seems intersting:
0262 $result = @odbc_exec($this->connection, $query);
0738 $id = @odbc_exec($this->connection, "SELECT * FROM $result");
0327 $result = @pg_exec($this->connection, 'begin;');
0334 $result = @pg_exec($this->connection, $query);
0611 $result = @pg_exec($this->connection, 'end;');
0631 $result = @pg_exec($this->connection, 'abort;');
0896 $id = @pg_exec($this->connection, "SELECT * FROM $result LIMIT 0");
0978 $result = @pg_exec($this->connection, "SELECT f.attnotnull, f.atthasdef
0989 $result = @pg_exec($this->connection, "SELECT a.adsrc
1001 $result = @pg_exec($this->connection, "SELECT i.indisunique, i.indisprimary, i.indkey
Can we do something based on this lines?
The Roundcube site is www.roundcube.net
The folder that i found the files with those lines is /program/lib/DB/
thanks |
|
|
|
|
|
|
|
|
Posted: Fri Jul 27, 2007 4:50 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
I downloaded that software and looked @ src code for ~10 minutes. And it seems to be written insecurely, towards to sql injection possibilities.
So hopefully I have more free time later and then will test soft in action and then let's see |
|
|
|
|
Posted: Sat Jul 28, 2007 12:19 am |
|
|
zer0-c00l |
Advanced user |
|
|
Joined: Jun 25, 2004 |
Posts: 72 |
Location: BRAZIL! |
|
|
|
|
|
|
thanks waraxe
btw, where can i find some material to learn about sql injection, to search vulnerabilities in PHP scripts like Roundcube, phpBB..?
Again, thanks for your help |
|
|
|
|
Posted: Sat Jul 28, 2007 7:40 am |
|
|
pexli |
Valuable expert |
|
|
Joined: May 24, 2007 |
Posts: 665 |
Location: Bulgaria |
|
|
|
|
|
|
|
|
|
|
Posted: Mon Jul 30, 2007 3:41 am |
|
|
zer0-c00l |
Advanced user |
|
|
Joined: Jun 25, 2004 |
Posts: 72 |
Location: BRAZIL! |
|
|
|
|
|
|
|
|
|
|
www.waraxe.us Forum Index -> All other security holes
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|