TorrentTrader Classic 'scrape.php' SQL Injection Vulnerability
BID:29451
Info
TorrentTrader Classic 'scrape.php' SQL Injection Vulnerability
| Bugtraq ID: | 29451 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6418 |
| Remote: | Yes |
| Local: | No |
| Published: | May 31 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | Charles Vaughn |
| Vulnerable: |
TorrentTrader TorrentTrader Classic Edition 1.08 TorrentTrader TorrentTrader Classic Edition 1.07 TorrentTrader TorrentTrader Classic Edition 1.06 TorrentTrader TorrentTrader 1.0 |
| Not Vulnerable: | |
Discussion
TorrentTrader Classic 'scrape.php' SQL Injection Vulnerability
TorrentTrader Classic is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
TorrentTrader Classic is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
TorrentTrader Classic 'scrape.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/scrape.php?info_hash=%22union%20select%201,1,1,1,ip%20from%20users--%20%20%20
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/scrape.php?info_hash=%22union%20select%201,1,1,1,ip%20from%20users--%20%20%20
Solution / Fix
TorrentTrader Classic 'scrape.php' SQL Injection Vulnerability
Solution:
This issue has been addressed in the May 2008 revision of Torrent Classic 1.08.
TorrentTrader TorrentTrader 1.0
TorrentTrader TorrentTrader Classic Edition 1.07
TorrentTrader TorrentTrader Classic Edition 1.08
TorrentTrader TorrentTrader Classic Edition 1.06
Solution:
This issue has been addressed in the May 2008 revision of Torrent Classic 1.08.
TorrentTrader TorrentTrader 1.0
-
TorrentTrader TorrentTraderClassic_v1.08.zip
http://downloads.sourceforge.net/torrenttrader/TorrentTraderClassic_v1 .08.zip?modtime=1210690965&big_mirror=0
TorrentTrader TorrentTrader Classic Edition 1.07
-
TorrentTrader TorrentTraderClassic_v1.08.zip
http://downloads.sourceforge.net/torrenttrader/TorrentTraderClassic_v1 .08.zip?modtime=1210690965&big_mirror=0
TorrentTrader TorrentTrader Classic Edition 1.08
-
TorrentTrader TorrentTraderClassic_v1.08.zip
http://downloads.sourceforge.net/torrenttrader/TorrentTraderClassic_v1 .08.zip?modtime=1210690965&big_mirror=0
TorrentTrader TorrentTrader Classic Edition 1.06
-
TorrentTrader TorrentTraderClassic_v1.08.zip
http://downloads.sourceforge.net/torrenttrader/TorrentTraderClassic_v1 .08.zip?modtime=1210690965&big_mirror=0
References
TorrentTrader Classic 'scrape.php' SQL Injection Vulnerability
References:
References:
- Release Name: FINAL v1.08 (TorrentTrader)
- TorrentTrader Homepage (TorrentTrader)
- SQL Injection leading to authorization bypass in Torrent Trader Classic v1.08 an ("Charles Vaughn"
)