Elgg 'tag_names' Parameter SQL Injection Vulnerability
BID:49237
Info
Elgg 'tag_names' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 49237 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 18 2011 12:00AM |
| Updated: | Aug 18 2011 12:00AM |
| Credit: | YGN Ethical Hacker Group |
| Vulnerable: |
Curverider Elgg 1.7.9 Curverider Elgg 1.7.8 Curverider Elgg 1.7.10 Curverider Elgg 1.6 Curverider Elgg 1.5 Curverider Elgg 1.0 |
| Not Vulnerable: |
Curverider Elgg 1.7.11 |
Discussion
Elgg 'tag_names' Parameter SQL Injection Vulnerability
Elgg is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Elgg 1.7.10 is vulnerable; other versions may also be affected.
Elgg is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Elgg 1.7.10 is vulnerable; other versions may also be affected.
Exploit / POC
Elgg 'tag_names' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/pg/search/?q=SQLin&search_type=tags&tag_names=location%27
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/pg/search/?q=SQLin&search_type=tags&tag_names=location%27
Solution / Fix
Elgg 'tag_names' Parameter SQL Injection Vulnerability
Solution:
The vendor released an update. Please see the references for details.
Curverider Elgg 1.0
Curverider Elgg 1.5
Curverider Elgg 1.7.10
Curverider Elgg 1.6
Curverider Elgg 1.7.8
Curverider Elgg 1.7.9
Solution:
The vendor released an update. Please see the references for details.
Curverider Elgg 1.0
-
Curverider elgg-1.7.11.zip
http://elgg.org/getelgg.php?forward=elgg-1.7.11.zip
Curverider Elgg 1.5
-
Curverider elgg-1.7.11.zip
http://elgg.org/getelgg.php?forward=elgg-1.7.11.zip
Curverider Elgg 1.7.10
-
Curverider elgg-1.7.11.zip
http://elgg.org/getelgg.php?forward=elgg-1.7.11.zip
Curverider Elgg 1.6
-
Curverider elgg-1.7.11.zip
http://elgg.org/getelgg.php?forward=elgg-1.7.11.zip
Curverider Elgg 1.7.8
-
Curverider elgg-1.7.11.zip
http://elgg.org/getelgg.php?forward=elgg-1.7.11.zip
Curverider Elgg 1.7.9
-
Curverider elgg-1.7.11.zip
http://elgg.org/getelgg.php?forward=elgg-1.7.11.zip
References
Elgg 'tag_names' Parameter SQL Injection Vulnerability
References:
References:
- Elgg 1.7.11 Release Notes (Curverider)
- Elgg Homepage (Curverider)
- Elgg 1.7.10 <= | Multiple Vulnerabilities (YGN Ethical Hacker Group
)