OpenBB 1.06 SQL Injection

n.teusink_at_planet.nl
Date: 12/26/03

  • Next message: http-equiv_at_excite.com: "DANGER ZONE: Internet Explorer"
    To: bugtraq@securityfocus.com
    Date: Fri, 26 Dec 2003 21:37:10 +0100
    
    

    Hello bugtraq readers,

    A vulnerability exists in OpenBB 1.06 that could allow an attacker to manipulate SQL
    queries and obtain sensitive information from the database such as the administrator
    md5 password hash.
    This vulnerability exists because the index.php script of the application does not
    sufficiently sanitize the input of the "CID" parameter.

    As far as I know this vulnerability can only be exploited if the database server the
    forum uses supports the UNION keyword, so it is probably not exploitable with
    MySQL 3.x. I have succesfully exploited this issue when using MySQL 4 as the
    database server.

    Impact
    ------

    If the admin password is weak enough the attacker could crack it using a brute force
    password cracker on the hash and get full control over the forum.

    Solution
    --------

    I have notified the OpenBB developers and they have very quickly (a couple of hours,
    great work guys!) released a patched version. You can also patch your forum
    manually as described in the OpenBB advisory:
    http://forums.openbb.com/read.php?TID=445

    Cheers,

    Niels Teusink

    http://www.teusink.net


  • Next message: http-equiv_at_excite.com: "DANGER ZONE: Internet Explorer"

    Relevant Pages

    • [Full-Disclosure] OpenBB 1.06 SQL Injection
      ... A vulnerability exists in OpenBB 1.06 that could allow an attacker to ... queries and obtain sensitive information from the database such as ...
      (Full-Disclosure)
    • SQL injection bug found in TBSource.
      ... A vulnerability found in the popular bittorrent tracker TBSource code allows an attacker to inject SQL queries and read secret information from the database. ...
      (Bugtraq)
    • [HV-HIGH] Microsoft Jet DB engine vulnerabilities
      ... Microsoft Jet database is a lightweight database widely used by MS Office ... This advisory is focused on just one vulnerability ... About HexView: ...
      (Bugtraq)
    • [Full-disclosure] [HV-HIGH] Microsoft Jet DB engine vulnerabilities
      ... Microsoft Jet database is a lightweight database widely used by MS Office ... This advisory is focused on just one vulnerability ... About HexView: ...
      (Full-Disclosure)
    • [Full-Disclosure] Symantec Buys SecurityFocus, among others....
      ... >As a consulting company that publishes vulnerability information and tools, ... FYI, as I recall, the information in the Bugtraq Database is freely available to the public through their web site anyways. ... The open source tools could tie into it. ... And I believe the same applies to Marty, as Sourcefire is offering commercial products built on Snort. ...
      (Full-Disclosure)