lucidCMS Login SQL Injection Vulnerability
BID:14976
Info
lucidCMS Login SQL Injection Vulnerability
| Bugtraq ID: | 14976 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 29 2005 12:00AM |
| Updated: | Sep 29 2005 12:00AM |
| Credit: | rgod is credited with the discovery of this vulnerability. |
| Vulnerable: |
lucidCMS lucidCMS 2.0.0 RC4 |
| Not Vulnerable: | |
Discussion
lucidCMS Login SQL Injection Vulnerability
lucidCMS is prone to to an SQL injection vulnerability.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Ultimately an attacker could exploit this vulnerability to gain administrative privileges. This could facilitate a compromise of the underlying system; other attacks are also possible.
lucidCMS is prone to to an SQL injection vulnerability.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Ultimately an attacker could exploit this vulnerability to gain administrative privileges. This could facilitate a compromise of the underlying system; other attacks are also possible.
Exploit / POC
lucidCMS Login SQL Injection Vulnerability
No exploit is required.
The following proof of concept demonstrates data to be entered into the login and password fields of the login page:
login: 'UNION(SELECT'1','admin','admin','[email protected]','d41d8cd98f00b204e9800998ecf8427e','1')/*
pass: [nothing]
No exploit is required.
The following proof of concept demonstrates data to be entered into the login and password fields of the login page:
login: 'UNION(SELECT'1','admin','admin','[email protected]','d41d8cd98f00b204e9800998ecf8427e','1')/*
pass: [nothing]
Solution / Fix
lucidCMS Login SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
lucidCMS Login SQL Injection Vulnerability
References:
References:
- lucidCMS Web Site (lucidCMS)
- rgod Website (rgod)
- Lucid CMS 1.0.11 SQL Injection / Login Bypass / remote code execution (rgod)