 |
Menu |
 |
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
 |
User Info |
 |
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 64
Members: 0
Total: 64
|
|
|
|
|
 |
Full disclosure |
 |
CyberDanube Security Research 20251014-0 | Multiple Vulnerabilities in Phoenix Contact QUINT4 UPS
apis.google.com - Insecure redirect via __lu parameter(exploited in the wild)
Urgent Security Vulnerabilities Discovered in Mercku Routers Model M6a
Re: Security Advisory: Multiple High-Severity Vulnerabilities in Suno.com (JWT Leakage, IDOR, DoS)
Security Advisory: Multiple High-Severity Vulnerabilities in Suno.com (JWT Leakage, IDOR, DoS)
[SBA-ADV-20250730-01] CVE-2025-39664: Checkmk Path Traversal
[SBA-ADV-20250724-01] CVE-2025-32919: Checkmk Agent Privilege Escalation via Insecure Temporary Files
CVE-2025-59397 - Open Web Analytics SQL Injection
Re: [FD]Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Re: Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Re: Defense in depth -- the Microsoft way (part 93): SRP/SAFERwhitelisting goes black on Windows 11
Re: [FD]: "Glass Cage" – Zero-Click iMessage ? Persistent iOS Compromise + Bricking (CVE-2025-24085 / 24201, CNVD-2025-07885)
Re: [FD]Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Samtools v1.22.1 Uncontrolled Memory Allocation from Large BED Intervals Causes Denial-of-Service in Samtools/HTSlib
Samtools v1.22.1 Improper Handling of Excessive Histogram Bin Counts in Samtools Coverage Leads to Stack Overflow
|
|
|
|
|
|
 |
|
 |
 |
|
 |
IT Security and Insecurity Portal |
|
 |
vBulletin <= 3.5.4 with MKPortal 1.1 Remote SQL Injection |
 |
Posted: Sat May 06, 2006 12:41 pm |
|
|
waraxe |
Site admin |

 |
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
 |
 |
 |
|
Original source:
http://www.nukedx.com/?viewdoc=26
Code: |
--Security Report--
Advisory: vBulletin <= 3.5.4 with MKPortal 1.1 Remote SQL Injection
Vulnerability.
---
Author: Mustafa Can Bjorn "nukedx a.k.a nuker" IPEKCI
---
Date: 21/04/06 22:36 PM
---
Contacts:{
ICQ: 10072
MSN/Email: nukedx@nukedx.com
Web: http://www.nukedx.com
}
---
Vendor: MKPortal (http://www.mkportal.it/)
Version: 1.1 RC1 and prior versions must be affected. (Runs on vBulletin!)
About: Via this methods remote attacker can inject arbitrary SQL queries to
ind parameter in index.php of MKPortal.
Vulnerable code can be found in the file
mkportal/include/VB/vb_board_functions.php at line 35-37, as you can see it
easy to
by pass this SQL update function.
Also there is cross-site scripting vulnerability in pm_popup.php the
parameters u1,m1,m2,m3,m4 did not sanitized properly.
Level: Critical
---
How&Example:
SQL Injection :
GET -> http://[victim]/[mkportaldir]/index.php?ind=[SQL]
EXAMPLE -> http://[victim]/[mkportaldir]/index.php?ind=',userid='1
So with this example remote attacker updates his session's userid to 1 and
after refreshing the page he can logs as userid 1.
XSS:
GET ->
http://[victim]/[mkportaldir]/includes/pm_popup.php?u1=[XSS]&m1=[XSS]&m2=[XSS]&m3=[XSS]&m4=[XSS]
---
Timeline:
* 21/04/2006: Vulnerability found.
* 21/04/2006: Contacted with vendor and waiting reply.
---
Exploit:
http://www.nukedx.com/?getxpl=26
---
Dorks: "MKPortal 1.1 RC1"
---
Original advisory can be found at: http://www.nukedx.com/?viewdoc=26
|
|
|
|
|
|
 |
 |
|
 |
Posted: Mon Jul 03, 2006 8:28 pm |
|
|
superninja |
Active user |

 |
|
Joined: Jul 03, 2006 |
Posts: 38 |
|
|
|
 |
 |
 |
|
k but where must i put this script? |
|
|
|
|
Posted: Tue Jul 04, 2006 1:36 pm |
|
|
Chb |
Valuable expert |

 |
|
Joined: Jul 23, 2005 |
Posts: 206 |
Location: Germany |
|
|
 |
 |
 |
|
Lolmao, this is not a script. It's a advisory. Just read it. |
|
|
|
|
Posted: Tue Jul 04, 2006 2:41 pm |
|
|
superninja |
Active user |

 |
|
Joined: Jul 03, 2006 |
Posts: 38 |
|
|
|
 |
 |
 |
|
whats http://[victim]/[mkportaldir]/includes/pm_popup.php?u1=[XSS]&m1=[XSS]&m2=[XSS]&m3=[XSS]&m4=[XSS]
also
http://[victim]/[mkportaldir]/index.php?ind=[SQL]
what must i put there (the bold words)?[/b] |
|
|
|
|
Posted: Tue Jul 04, 2006 3:52 pm |
|
|
Chb |
Valuable expert |

 |
|
Joined: Jul 23, 2005 |
Posts: 206 |
Location: Germany |
|
|
 |
 |
 |
|
superninja wrote: | whats http://[victim]/[mkportaldir]/includes/pm_popup.php?u1=[XSS]&m1=[XSS]&m2=[XSS]&m3=[XSS]&m4=[XSS] |
Victim: Take a look into a directory... You got to put your victim there.
mkportaldir: mkportal directory path...
XSS: Your Cross Site Scripting.
Quote: | http://[victim]/[mkportaldir]/index.php?ind=[SQL] |
SQL: A SQL-Query for SQL-injection. |
|
|
|
|
 |
 |
|
 |
Posted: Tue Jul 04, 2006 8:15 pm |
|
|
superninja |
Active user |

 |
|
Joined: Jul 03, 2006 |
Posts: 38 |
|
|
|
 |
 |
 |
|
Chb wrote: | superninja wrote: | whats http://[victim]/[mkportaldir]/includes/pm_popup.php?u1=[XSS]&m1=[XSS]&m2=[XSS]&m3=[XSS]&m4=[XSS] |
Victim: Take a look into a directory... You got to put your victim there.
mkportaldir: mkportal directory path...
XSS: Your Cross Site Scripting.
Quote: | http://[victim]/[mkportaldir]/index.php?ind=[SQL] |
SQL: A SQL-Query for SQL-injection. |
mkportaldir is /forum /phpbb or /forums??
also
XSS i where is XSS? |
|
|
|
|
Posted: Tue Jul 04, 2006 11:29 pm |
|
|
waraxe |
Site admin |

 |
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
 |
 |
 |
|
|
|
|
|
 |
 |
|
 |
Posted: Sat Jul 08, 2006 7:12 am |
|
|
cheaparse |
Beginner |

 |
|
Joined: Jun 27, 2006 |
Posts: 2 |
|
|
|
 |
 |
 |
|
ahh this is great, but does anyone have any other exploits / advisories for vbulletin 3.5.4 WITHOUT mkportal?
what if you're on a board where they have to verify your sign ups? so that means that you sign up, and you can log into your profile, but you CANNOT send private messages or post any messages (there goes XSS out the window)?
As for the impex exploit, it is there, but you get error messages when you try for file inclusion (this includes from all 3 impex files). i don't understand why.. i tried it for another 3.5.4 and it was successful.. but that was very rare
P.S. all i want to do is make my account active.. if you know any workarounds for vb 3.5.4 let me (and others if you don't mind) know  |
|
|
|
|
Posted: Sat Jul 08, 2006 11:32 pm |
|
|
superninja |
Active user |

 |
|
Joined: Jul 03, 2006 |
Posts: 38 |
|
|
|
 |
 |
 |
|
Whats MKportal i know whats XSS already now i learned something but what's mkportal ?
And someone give me some XSS text  |
|
|
|
|
www.waraxe.us Forum Index -> vBulletin Board
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|