what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

OpenDocMan 1.2.6.2 SQL Injection / Access Bypass

OpenDocMan 1.2.6.2 SQL Injection / Access Bypass
Posted Dec 13, 2012
Authored by Kenneth F. Belva

OpenDocMan version 1.2.6.2 suffers from remote SQL injection and multiple access bypass vulnerabilities.

tags | exploit, remote, vulnerability, sql injection, bypass
SHA-256 | b865110065c53e1f31eed37d7378c899a40f17fdecd48dbbcec488cf1491d1be

OpenDocMan 1.2.6.2 SQL Injection / Access Bypass

Change Mirror Download
#1 - Unprotected id parameter
-----------------------------
In check-in.php the id variable is not filtered so that one can put in
additional SQL statements. I have been able to get a UNION SELECT query
to run but I do not think it's exploitable because there is a second
query that runs with the id variable that will fail. None-the-less it is
possible to get my string to the interpreter as valid SQL.

#2 - Password reset allows anyone to reset the admin password
-------------------------------------------------------------
forgot_password.php does not have any authentication or checking to make
sure the user is only changing their password. So, an unauthenticated
user can reset the password of any account if this functionality is
enabled. It is disabled by default.

#3 - ACL broken for restricted documents
----------------------------------------
Assume a user uploads a file and put restricted access control around it
preventing any other users from accessing it through the software
interface. If an attacker were to change the aku parameter to include
the restricted file number they would be able to use the check-out.php
page to retrieve the restricted file.


Thanks to Stephen Laurence, the developer for this OSS project, for the
quick replies. These issues were addressed by the developer (although I
did not test the changes). Please download the latest version.

Ken
http://silverbackventuresllc.com
Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    0 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close