exploits , vulnerabilities , articles , VBulletin Multiple Moderator And Administrator SQL Injection Vulnerabilities
| Title |
VBulletin Multiple Moderator And Administrator SQL Injection Vulnerabilities |
| Published |
2005-09-19-12:00AM |
| Updated |
2005-09-19-04:05PM |
| Class |
Input Validation Error |
| CVE |
CVE-MAP-NOMATCH |
| Remote |
Yes |
| Local |
No |
| Credit |
deluxe <deluxe@security-project.org> is credited with the discovery of this vulnerability. |
| Vulnerable |
VBulletin VBulletin 3.0.8
VBulletin VBulletin 3.0.7
VBulletin VBulletin 3.0.6
VBulletin VBulletin 3.0.5
VBulletin VBulletin 3.0.4
VBulletin VBulletin 3.0.3
VBulletin VBulletin 3.0.2
VBulletin VBulletin 3.0.1
VBulletin VBulletin 3.0 Gamma
VBulletin VBulletin 3.0 beta 7
VBulletin VBulletin 3.0 beta 6
VBulletin VBulletin 3.0 beta 5
VBulletin VBulletin 3.0 beta 4
VBulletin VBulletin 3.0 beta 3
VBulletin VBulletin 3.0 beta 2
VBulletin VBulletin 3.0
VBulletin VBulletin 2.3.4
VBulletin VBulletin 2.3.3
VBulletin VBulletin 2.3.2
VBulletin VBulletin 2.3 .0
VBulletin VBulletin 2.2.9
VBulletin VBulletin 2.2.8
VBulletin VBulletin 2.2.7
VBulletin VBulletin 2.2.6
VBulletin VBulletin 2.2.5
VBulletin VBulletin 2.2.4
VBulletin VBulletin 2.2.3
VBulletin VBulletin 2.2.2
VBulletin VBulletin 2.2.1
VBulletin VBulletin 2.2 .0
VBulletin VBulletin 2.0.3
VBulletin VBulletin 2.0 rc 3
VBulletin VBulletin 2.0 rc 2
VBulletin VBulletin 1.0.1 lite |
| Not Vulnerable |
VBulletin VBulletin 3.0.9 |
| Code |
No exploit is required.
The following GET and POST proof of concepts are available: The following issue is exploitable by any attacker: > /joinrequests.php: POST: <do=processjoinrequests&usergroupid=22&request[[SQL-Injection]]=0>
These issues affect the following administrator scripts: > /admincp/admincalendar.php: GET: <do=addcustom&calendarcustomfieldid=[SQL-Injection]> GET: <do=addmod&calendarid=[SQL-Injection]> GET: <do=addmod&calendarid=1&moderatorid=[SQL-Injection]> GET: <do=deletecustom&calendarcustomfieldid=[SQL-Injection]> POST: <do=doremoveholiday&holidayid=[SQL-Injection]> GET: <do=edit&calendarid=[SQL-Injection]> POST: <do=kill&calendarid=[SQL-Injection]> POST: <do=killmod&$calendarmoderatorid=[SQL-Injection]> GET: <do=remove&calendarid=[SQL-Injection]> POST: <do=removemod&moderatorid=[SQL-Injection]> POST: <do=saveholiday&holidayinfo[title]=sepro&holidayid=0XF> POST: <do=update&calendar[daterange]=2002-2008&calendarid=0XF> GET: <do=updateholiday&holidayid=0XF> POST: <do=update&calendarid=1&calendar[daterange]=1970-2030& calendar[0]=[SQL-Injection]> POST: <do=updatemod&calendarid=1&moderatorid=[SQL-Injection]> POST: <do=updatemod&moderatorid=1&moderator[calendarid]=[SQL-Injection]>
> /admincp/cronlog.php: POST: <do=doprunelog&cronid=0XF> POST: <do=prunelog&cronid=0XF>
> /admincp/email.php: POST: <do=makelist&user[usergroupid][0]=[SQL-Injection]>
> /admincp/help.php: POST: <do=doedit&help[script]=1&help[0]=[SQL-Injection]>
> /admincp/user.php: GET: <do=find&orderby=username&limitnumber=[SQL-Injection]> GET: <do=find&orderby=username&limitstart=[SQL-Injection]>
> /admincp/usertitle.php: GET: <do=edit&usertitleid=0XF> GET: <do=pmuserstats&ids=0XF>
> /admincp/language.php: POST: <do=update&rvt[0]=[SQL-Injection]>
> /admincp/phrase.php: POST: <do=completeorphans&keep[0]=[SQL-Injection]>
> /admincp/template.php: GET: <do=editstyle&dostyleid=[SQL-Injection]> GET: <do=editstyle&dostyleid=[SQL-Injection]> POST: <do=revertall&dostyleid=[SQL-Injection]>
> /admincp/thread.php:: POST: <do=dothreads&thread[forumid]=0XF>
> /admincp/usertools.php: POST: <do=updateprofilepic>
> /admincp/vbugs_admin.php: GET: <do=editseverity&vbug_severityid=[SQL-Injection]> GET: <do=removeseverity&vbug_severityid=[SQL-Injection]> GET: <do=updateseverity&vbug_severityid=[SQL-Injection]>
These issues affect the following moderator scripts: > /modcp/announcement.php: POST: <do=update&announcementid=1&start=24-07-05&end=30-07-05 &announcement[0]=[SQL-Injection]>
> /modcp/thread.php: POST: <do=dothreads&thread[forumid]=0XF> POST: <do=dothreadssel&criteria=a:1:{s:7:"forumid";s:5:"aaaa'";}>
> /modcp/user.php: GET: <do=avatar&userid=0XF>
|
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Fri, 11 Dec 2009 11:55:10 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
/search/ex %2Fcompone WWWSEX300 /component dragon fab Free musli Sexy malay WWWSEX300 t644t Tagger LE Dis phpBB by P new sexfli WWW.MIYABI ww.89.cm// Kayako null search/exp elxis shopexd.as php-nuke 2 Windows MS Www.XXX vi Free horse ji0537.com Nokia IPSO phalistine arab sex6 kernel 2.2 mambo Remo sexayvidio ScHool.Gir onlinesex Indiyn por TRISHASEXW Foto artis Www.sexy p onlinesex video pilm sexpichers news for C www.bjhzjt FileZilla Free sex v php-nuke 2 phpnuke pl EVO libdb www.chengs Up results
|