Date: Fri, 18 Mar 2011 14:15:25 +0800 From: YGN Ethical Hacker Group <lists@...g.net> To: oss-security@...ts.openwall.com Subject: CVE Request: Joomla! 1.5.21 <= SQL Injection Vulnerability 1. OVERVIEW Potential SQL Injection Flaws were detected Joomla! CMS version 1.5.20. 2. PRODUCT DESCRIPTION Joomla is a free and open source content management system (CMS) for publishing content on the World Wide Web and intranets. It comprises a model–view–controller (MVC) Web application framework that can also be used independently. Joomla is written in PHP, uses object-oriented programming (OOP) techniques and software design patterns, stores data in a MySQL database, and includes features such as page caching, RSS feeds, printable versions of pages, news flashes, blogs, polls, search, and support for language internationalization. 3. VULNERABILITY DESCRIPTION Parameters (filter_order, filer_order_Dir) were not properly sanitized in Joomla! that lead to SQL Injection vulnerability. 4. VERSIONS AFFECTED Joomla! 1.5.21 and lower 5. PROOF-OF-CONCEPT/EXPLOIT Exploits: /index.php?option=com_weblinks&view=category&id=2&filter_order_Dir=&filter_order=%00' /index.php?option=com_weblinks&view=category&id=2&filter_order_Dir='&filter_order=asc Screenshots: http://yehg.net/lab/pr0js/advisories/joomla/core/1.5.21/sql_injection/sqli_(filter_order)_front.jpg http://yehg.net/lab/pr0js/advisories/joomla/core/1.5.21/sql_injection/sqli_%28filter_order_Dir%29_front.jpg http://yehg.net/lab/pr0js/advisories/joomla/core/1.5.21/sql_injection/sqli_%28filter_order_Dir%29_back.jpg 6. IMPACT Attackers could successfully execution malicious sql command injection in Joomla! CMS by bypassing filers in place. 7. SOLUTION Upgrade to Joomla! 1.5.22 8. VENDOR Joomla! Developer Team http://www.joomla.org 9. CREDIT This vulnerability was discovered by Aung Khant, http://yehg.net, YGN Ethical Hacker Group, Myanmar. 10. DISCLOSURE TIME-LINE 2010-10-06 : Notified Joomla! Security Strike Team 2010-11-01 : Vulnerability disclosed 2010-11-05 : Patched version (1.5.22) released 11. REFERENCES Vendor Advisory URL: http://developer.joomla.org/security/news/9-security/10-core-security/323-20101101-core-sqli-info-disclosurevulnerabilities.html Original Advisory URL: http://yehg.net/lab/pr0js/advisories/joomla/core/[joomla_1.5_21]_sql_injection Assigned CVE: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-4166 OWASP Top 10: http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project CWE-89: http://cwe.mitre.org/data/definitions/89.html #yehg [2010-11-05] last updated: 2010-12-24
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.