Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-disclosure] RE: Advisory: Eggblog <= 3.x Multiple Remote Vulnerabilities |
|---|---|
| Date: | Mon, 29 May 2006 17:42:52 +0100 |
These issues have been fixed as of v3.07. v2 is not supported and should no longer be available to download. Please let me know if this is not the case. Thanks, Egg www.eggblog.net -----Original Message----- From: Mustafa Can Bjorn IPEKCI [mailto:nukedx@nukedx.com] Sent: 28 May 2006 15:01 To: submit@milw0rm.com; full-disclosure@lists.grok.org.uk; bugtraq@securityfocus.com; egg@epicdesigns.co.uk Subject: Advisory: Eggblog <= 3.x Multiple Remote Vulnerabilities --Security Report-- Advisory: Eggblog <= 3.x Multiple Remote Vulnerabilities --- Author: Mustafa Can Bjorn "nukedx a.k.a nuker" IPEKCI --- Date: 27/05/06 06:15 PM --- Contacts:{ ICQ: 10072 MSN/Email: nukedx@nukedx.com Web: http://www.nukedx.com } --- Vendor: Eggblog (http://www.eggblog.net/) Version: 3.0.6 and prior versions must be affected. About: Via this method remote attacker can inject arbitrary SQL queries to Eggblog.This SQL injection works with Eggblog version 3.0.6 and below.The problem is that id parameter id rss/posts.php did not sanitized properly before using it in SQL query.This caused to remote attacker inject arbitrary SQL queries and execute them.This SQL injection needs magic_quotes_gpc off. There is another problem in Eggblog 2.x.In registration member register status did not sanitized properly.This caused to remote attacker "register new member" as a admin nick and get administration privileges on Eggblog. Level: Critical --- How&Example: GET -> http://[site]/[EggBlog]/rss/posts.php?id=SQL EXAMPLE -> http://[site]/[EggBlog]/rss/posts.php?id=1'/**/UNION/**/SELECT/**/0,concat(' Username:%20',username), concat('Password:%20',password)/**/from/**/eggblog_members/* POST/EXAMPLE -> http://[site]/[EggBlog]/home/register.php?username=victim&password=password& email=e@mail.com&ref= -- Timeline: * 27/05/2006: Vulnerability found. * 27/05/2006: Contacted with vendor and waiting reply. --- Exploit: http://www.nukedx.com/?getxpl=36 --- Original advisory can be found at: http://www.nukedx.com/?viewdoc=36 _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Advisory: ASPBB <= 0.52 (perform_search.asp) XSS vulnerability, Mustafa Can Bjorn IPEKCI |
|---|---|
| Next by Date: | VARIOMAT(advanced cms tool)SQL injection/XSS, CrAzY . CrAcKeR |
| Previous by Thread: | [Full-disclosure] Advisory: Eggblog <= 3.x Multiple Remote Vulnerabilities, Mustafa Can Bjorn IPEKCI |
| Next by Thread: | [Full-disclosure] Advisory: phpBB 2.x (admin/admin_hacks_list.php) Local Inclusion Vulnerability., Mustafa Can Bjorn IPEKCI |
| Indexes: | [Date] [Thread] [Top] [All Lists] |