Members: 16,996
Threads: 38,846
Posts: 159,391
Online: 18

Newest Member: Kl_broka@rediffmail.com


Odoo.tv - Outdoor Television


Sedo - Domains kaufen und verkaufen das Projekt mambers.com steht zum Verkauf Besucherstatistiken von mambers.com etracker® Web-Controlling statt Logfile-Analyse

Go Back   Mambers.com > Mambo 4.5.1 > Mambo 4.5.1 Bugs

Reply
 
LinkBack Thread Tools Display Modes
Old 23.12.2004, 10:46   #1 (permalink)
Baby Mamber
 
Join Date: Nov 2004
Posts: 9
MrSleep is on a distinguished road
Default Sql injection in Akogallery 2.5b In Mambo 4.5.1a?

When I hit
http://www.piratesahoy.net/component/option,com_akogallery/Itemid,36/func,detail/id,22'/

, I get the following error:

Notice: You have an error in your SQL syntax. Check the manual that corresponds to your MySQL server version for the right syntax to use near '\'' at line 3 in /var/www/html/includes/database.php on line 202


Any help will be greatly appeciated.

Thanks
MrSleep
MrSleep is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Old 23.12.2004, 12:25   #2 (permalink)
Senior Mamber
 
novocaine's Avatar
 
Join Date: Apr 2004
Location: Hamburg/Germany
Posts: 241
novocaine is on a distinguished road
Default Re: Sql injection in Akogallery 2.5b In Mambo 4.5.1a?

Note the apostrophe after the 22? This causes the error
[...]id,22'/
If you click the below link, you'll see that there is no error:
http://www.piratesahoy.net/component...,detail/id,22/
__________________
Visit ThinkMambo - home of TMEdit and XHTMLSuite
WYSIWYG editors for Mambo Open Source
novocaine is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 25.12.2004, 06:20   #3 (permalink)
Baby Mamber
 
Join Date: Nov 2004
Posts: 9
MrSleep is on a distinguished road
Default Re: Sql injection in Akogallery 2.5b In Mambo 4.5.1a?

Right, but hacker can exploit with:

http://www.piratesahoy.net/index.php...okie)</script>

Cross-Site Scripting via Multiple SQL Injection Vulnerabilities!!!

The script is vulnerable to SQL injections. The injection opportunity is after the "ORDER BY" keywords in the SQL query, so the "UNION" method will not work to exploit this opportunity. However, Akog displays SQL error messages (implemented in database.php.) Therefore, an attacker could pass in script code as part of the injected SQL that generates an SQL error, thereby transforming the SQL injection vulnerability into a cross-site scripting vulnerability. One example of this technique is with SQL injection in it:

http://host/index.php?option=com_ako...unc=detail&id=[SQL code]

which could be exploited as:
http://host/index.php?option=com_ako...unc=detail&id=[SQL code]><script>alert(document.cookie)</script>

earlier is vulnerable.
MrSleep is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
TUTORIAL: How to INTEGRATE Mambo modules into non-MOS static php pages in your site marcnyc Mambo 4.5 'How Do I' Questions 10 28.02.2006 04:23
Nach fehlerfreier Installation 'Fatal error' ricolein Installation 7 30.11.2004 04:16
funny sql errors on Mambo 4.5.1a website ultraman Mambo 4.5.1 'How Do I' Questions 4 03.11.2004 13:52
Module nebeneinander laden - Mambo 4.5.1a Nethawk Templates 1 28.10.2004 17:39
MOS no more - Mambo for sure ;) idigital Community Announcements 16 25.07.2004 06:14


All times are GMT +2. The time now is 12:55.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.1.0
A vBSkinworks Design
© Copyright 2004-2008 by Arthur Konze Webdesign.