OpenNews SQL Injection and Code Execution Vulnerabilities
BID:43164
Info
OpenNews SQL Injection and Code Execution Vulnerabilities
| Bugtraq ID: | 43164 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-2735 CVE-2009-2736 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 05 2009 12:00AM |
| Updated: | Aug 05 2009 12:00AM |
| Credit: | SirGod |
| Vulnerable: |
Lerie Taylor OpenNews 1.0 |
| Not Vulnerable: | |
Discussion
OpenNews SQL Injection and Code Execution Vulnerabilities
OpenNews is prone to an SQL-injection vulnerability and a code-execution vulnerability because it fails to sufficiently sanitize user-supplied data.
Successfully exploiting these issues may allow an attacker to compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or execute arbitrary PHP code in the context of the application.
OpenNews 1.0 is vulnerable; other versions may be affected.
OpenNews is prone to an SQL-injection vulnerability and a code-execution vulnerability because it fails to sufficiently sanitize user-supplied data.
Successfully exploiting these issues may allow an attacker to compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or execute arbitrary PHP code in the context of the application.
OpenNews 1.0 is vulnerable; other versions may be affected.
Exploit / POC
OpenNews SQL Injection and Code Execution Vulnerabilities
The following exploit data is available:
http://www.example.com/admin.php
Username : admin ' or ' 1=1
Password : anything
The following exploit data is available:
http://www.example.com/admin.php
Username : admin ' or ' 1=1
Password : anything
Solution / Fix
OpenNews SQL Injection and Code Execution Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
OpenNews SQL Injection and Code Execution Vulnerabilities
References:
References:
- OpenNews - Homepage (Lerie Taylor)