PDA

View Full Version : 'last.php' 3rd Party vBulletin Hack Lets Remote Users Inject SQL Commands


deepdark
11-15-2004, 12:50 PM
Input Validation Error in 'last.php' 3rd Party vBulletin Hack Lets Remote Users Inject SQL Commands

SecurityTracker Alert ID: *removed*
SecurityTracker URL: *link removed*
CVE Reference: GENERIC-MAP-NOMATCH (Links to External Site)
Updated: Nov 12 2004

Original Entry Date: Nov 11 2004

Impact: Disclosure of authentication information, Disclosure of system information, Disclosure of user information

Exploit Included: Yes

Description: An input validation vulnerability was reported in the 'last.php' hack for vBulletin. A remote user can inject SQL commands. The script is a 3rd party product and is not part of the vBulletin product.

Dr. Death reported that 'last.php' does not properly validate user-supplied input in the 'fsel' parameter. A remote user can submit a specially crafted HTTP request to inject SQL commands on the underlying database.

A demonstration exploit is provided:

*removed*

Impact: A remote user can execute SQL commands on the underlying database.

Solution: No solution was available at the time of this entry.

Cause: Input validation error

Underlying OS: Linux (Any), UNIX (Any), Windows (Any)

Reported By: "Dr. Death" <drdeath4ever@hotmail.com>

Message History: None.

__________________________________________________ ______________

Date: Thu, 11 Nov 2004 05:29:44 +0000
From: "Dr. Death" <drdeath4ever@hotmail.com>
Subject: SQL injection in vBulletin forums (last10.php)





hi all,

a new SQL injection found in VBulletin Forums 3.0.x

the Vulnerabilite found in last.php, last 10 topics hack.


*removed*

to solve the problem delet fsel? from ttlast.php and last10.php

Best Regards,
Dr.Death
THE MAN OF THE DARK SIDE


NEWS LINK:h*removed*

Zachery
11-15-2004, 01:15 PM
I would suggest altering the author :)

Freezerator
11-15-2004, 01:54 PM
it's better to know wich hack this is, so the maker of the hack can be notified?

deepdark
11-15-2004, 02:37 PM
i found this today and i writed here i think that this is not a bug is a backdoor for hacking.

Zachery
11-15-2004, 02:44 PM
i found this today and i writed here i think that this is not a bug is a backdoor for hacking.
Tell the AUTHOR OF THE HACK so they can FIX IT

Beermonster
11-15-2004, 03:00 PM
Tell the AUTHOR OF THE HACK so they can FIX IT


I think he might have got a bit confused with your first reply

I would suggest altering the author :)

shouldn't that have been alerting :D

Dean C
11-15-2004, 03:29 PM
I have removed your link and exploit details in case any malicious user here decided to take advantage. I've maintained a copy of your post behind the scenes for the staff to take a look at. Thankyou for alerting us and we'll contact the author.