Document Title: =============== Subrion v4.0.5 CMS - SQL Injection Vulnerability References (Source): ==================== http://ift.tt/2azBfYj Release Date: ============= 2016-08-04 Vulnerability Laboratory ID (VL-ID): ==================================== 1893 Common Vulnerability Scoring System: ==================================== 7 Product & Service Introduction: =============================== Subrion is a full featured open source CMS written in PHP 5 & MySQL with many options. Here is the list of the most important features. You don't need to pay a single penny to start using Subrion CMS. It's not encrypted in any way so you can customize it per your needs. It's done to focus on the content management process. Start it hassle-free within just a few minutes and take care of the content. (Copy of the Vendor Homepage: http://ift.tt/2a45l6h ) Abstract Advisory Information: ============================== The vulnerability laboratory core research team discovered a remote sql-injection vulnerability in the Subrion v4.0.5 content management system. Vulnerability Disclosure Timeline: ================================== 2016-08-04: Public Disclosure (Vulnerability Laboratory) Discovery Status: ================= Published Affected Product(s): ==================== Intelliants LLC Product: Subrion - Content Management System (Web-Application) 4.0.5 Exploitation Technique: ======================= Remote Severity Level: =============== High Technical Details & Description: ================================ A remote sql-injection web vulnerability has been discovered in the Subrion v4.0.5 content management system. The vulnerability allows remote attackers to execute own malicious sql commands to compromise the application or dbms. The sql-injection vulnerability is located in the `query` and ` show_query` parameters of the `.database/sql/` module POST method request. Remote attackers are able to execute own sql commands by usage of the insecure sql management tool request. The attack vector of the vulnerability is application-side and the request method to inject is POST. The security risk of the sql-injection vulnerability is estimated as high with a cvss (common vulnerability scoring system) count of 7.0. Exploitation of the remote sql injection web vulnerability requires no user interaction and a low privileged web-application user account. Successful exploitation of the remote sql injection results in database management system, web-server and web-application compromise. Request Method(s): [+] POST Vulnerable Module(s): [+] ./database/sql/ Vulnerable Parameter(s): [+] show_query [+] query Proof of Concept (PoC): ======================= The vulnerability can be exploited by remote attackers with privileged web-application user account and without user interaction. For security demonstration or to reproduce the vulnerability follow the provided information and steps below to continue. PoC: Exploitation
POST /admin/database/sql/ HTTP/1.1 Host: http://ift.tt/2aISjci query=[SQL-INJECTION VULNERABILITY!]&show_query=[SQL-INJECTION VULNERABILITY!]&exec_query=Go
Source: Gmail -> IFTTT-> Blogger
No comments:
Post a Comment