ADOdb Server.PHP SQL Injection Vulnerability
BID:16187
Info
ADOdb Server.PHP SQL Injection Vulnerability
| Bugtraq ID: | 16187 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-0146 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 09 2006 12:00AM |
| Updated: | May 29 2006 06:02PM |
| Credit: | Andreas Sandblad of Secunia Research is credited with the discovery of this vulnerability. |
| Vulnerable: |
Simplog Simplog 0.9.2 Planet Technology WSW-2401 0.8.6 g phpESP phpESP 1.8.1 phpESP phpESP 1.8 -rc1 phpESP phpESP 1.7.5 -dev3 phpESP phpESP 1.7.5 -dev2 phpESP phpESP 1.7.5 -dev phpESP phpESP 1.7.5 phpESP phpESP 1.7.2 phpESP phpESP 1.7.1 phpESP phpESP 1.7 PHP Link Directory PHPLD 2.0 Mantis Mantis 1.0 .0RC4 Mantis Mantis 0.19.4 LifeType LifeType 1.0.2 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 Cisco Aironet 340 BR340 Firmware 0.761 BEA Systems Weblogic Proxy Plugin 1.5.3 Agileco AgileBill 1.4.92 ADOdb ADOdb 4.68 ADOdb ADOdb 4.66 |
| Not Vulnerable: |
Planet Technology WSW-2401 0.8.6 h phpESP phpESP 1.8.2 Mantis Mantis 1.0 LifeType LifeType 1.0.3 Cisco Aironet 340 BR340 Firmware 0.761 a BEA Systems Weblogic Proxy Plugin 1.5.3 + Agileco AgileBill 1.4.93 ADOdb ADOdb 4.70 |
Discussion
ADOdb Server.PHP SQL Injection Vulnerability
ADOdb is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Exploitation of this issue requires the root password for MySQL to be empty and the affected script to be located inside the web root.
ADOdb is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Exploitation of this issue requires the root password for MySQL to be empty and the affected script to be located inside the web root.
Exploit / POC
ADOdb Server.PHP SQL Injection Vulnerability
An exploit is not required.
The following proof-of-concept URI is available:
http://www.example.com/server.php?sql=SELECT '[content]' INTO OUTFILE '[file]'
An exploit is not required.
The following proof-of-concept URI is available:
http://www.example.com/server.php?sql=SELECT '[content]' INTO OUTFILE '[file]'
Solution / Fix
ADOdb Server.PHP SQL Injection Vulnerability
Solution:
The vendor has released an update addressing this issue.
Please see the referenced vendor advisories for further information.
Mantis Mantis 0.19.4
Cisco Aironet 340 BR340 Firmware 0.761
Planet Technology WSW-2401 0.8.6 g
Mantis Mantis 1.0 .0RC4
LifeType LifeType 1.0.2
BEA Systems Weblogic Proxy Plugin 1.5.3
phpESP phpESP 1.7
phpESP phpESP 1.7.1
phpESP phpESP 1.7.2
phpESP phpESP 1.7.5 -dev2
phpESP phpESP 1.7.5
phpESP phpESP 1.7.5 -dev
phpESP phpESP 1.7.5 -dev3
phpESP phpESP 1.8 -rc1
phpESP phpESP 1.8.1
ADOdb ADOdb 4.66
ADOdb ADOdb 4.68
Solution:
The vendor has released an update addressing this issue.
Please see the referenced vendor advisories for further information.
Mantis Mantis 0.19.4
-
Mantis mantis-1.0.0.tar.gz
http://prdownloads.sourceforge.net/mantisbt/mantis-1.0.0.tar.gz
Cisco Aironet 340 BR340 Firmware 0.761
-
PostNuke PostNuke 0.761a
http://news.postnuke.com/Downloads-req-getit-lid-517.html
Planet Technology WSW-2401 0.8.6 g
-
Cacti cacti-0.8.6h.tar.gz
http://www.cacti.net/downloads/cacti-0.8.6h.tar.gz
Mantis Mantis 1.0 .0RC4
-
Mantis mantis-1.0.0.tar.gz
http://prdownloads.sourceforge.net/mantisbt/mantis-1.0.0.tar.gz
LifeType LifeType 1.0.2
-
LifeType lifetype-1.0.3.tar.gz
http://prdownloads.sourceforge.net/lifetype/lifetype-1.0.3.tar.gz
BEA Systems Weblogic Proxy Plugin 1.5.3
-
Moodle moodle-latest.tgz
This is the latest development version that will become version 1.3 of the software. The fix for this issue has been incorporated into the product and will be included in the next official release.
http://moodle.org/download.php/moodle/moodle-latest.tgz
phpESP phpESP 1.7
-
phpESP phpESP-1.8.2.tar.gz
http://prdownloads.sourceforge.net/phpesp/phpESP-1.8.2.tar.gz
phpESP phpESP 1.7.1
-
phpESP phpESP-1.8.2.tar.gz
http://prdownloads.sourceforge.net/phpesp/phpESP-1.8.2.tar.gz
phpESP phpESP 1.7.2
-
phpESP phpESP-1.8.2.tar.gz
http://prdownloads.sourceforge.net/phpesp/phpESP-1.8.2.tar.gz
phpESP phpESP 1.7.5 -dev2
-
phpESP phpESP-1.8.2.tar.gz
http://prdownloads.sourceforge.net/phpesp/phpESP-1.8.2.tar.gz
phpESP phpESP 1.7.5
-
phpESP phpESP-1.8.2.tar.gz
http://prdownloads.sourceforge.net/phpesp/phpESP-1.8.2.tar.gz
phpESP phpESP 1.7.5 -dev
-
phpESP phpESP-1.8.2.tar.gz
http://prdownloads.sourceforge.net/phpesp/phpESP-1.8.2.tar.gz
phpESP phpESP 1.7.5 -dev3
-
phpESP phpESP-1.8.2.tar.gz
http://prdownloads.sourceforge.net/phpesp/phpESP-1.8.2.tar.gz
phpESP phpESP 1.8 -rc1
-
phpESP phpESP-1.8.2.tar.gz
http://prdownloads.sourceforge.net/phpesp/phpESP-1.8.2.tar.gz
phpESP phpESP 1.8.1
-
phpESP phpESP-1.8.2.tar.gz
http://prdownloads.sourceforge.net/phpesp/phpESP-1.8.2.tar.gz
ADOdb ADOdb 4.66
-
ADOdb adodb470.tgz
http://prdownloads.sourceforge.net/adodb/adodb470.tgz
ADOdb ADOdb 4.68
-
ADOdb adodb470.tgz
http://prdownloads.sourceforge.net/adodb/adodb470.tgz
References
ADOdb Server.PHP SQL Injection Vulnerability
References:
References:
- ADOdb Insecure Test Scripts Security Issues (Secunia)
- ADOdb Lite Homepage (ADOdb)
- AgileBill 1.4.93 Fixed Bugs (Agileco)
- AgileBill ADOdb "server.php" Test Script Remote Code Execution Issue (FrSIRT)
- AgileBill v1.4.93 Released (Agileco)
- Bug for libs in php link directory (PHP Link Directory)
- Cacti Homepage (Cacti)
- Mantis Homepage (Mantis)
- Mantis release Name: 1.0.0 (Mantis)
- Moodle Home Page (Moodle)
- phpESP Homepage (phpESP)
- phpESP-1.8.2 Release Notes (phpESP)
- PostNuke Product Page (PostNuke)
- Vendor Homepage (Agileco)
- Bug for libs in php link directory 2.0 (Mario Oyorzabal Salgado
)