Get XOOPS XOOPS FAQ Forums News Themes Modules
New Posts New Topics All Forums Index General Modules Themes Development International XOOPS.org

XOOPS vs. Herko Coomans

Make a donation

Please select an amount to donate


Do you want your username revealed with your donation?
Yes - List me as a Generous Donor
No - List my donation as from an Anonymous Donor


Search

Local Support Sites

Cumulus Tag Cloud

admin Arabic banner block Christmas comments cumulus DayDawn dhsoft e-Commerce E-Learning Google GUI hacks instant-zero jQuery module news Nordic Olédrion oxygen PageRank security SEO simple-XOOPS sport tag Theme wiki xoops

New Users

Registering user

# 96568

dvsshoescom

Welcome to XOOPS!
XOOPS Code hosted on SourceForge


 Bottom   Previous Topic   Next Topic

1 2 3 »
#1 Posted on: 2007/2/6 8:56 Xoops Multiple Unspecified SQL Injection Vulnerabilities
Xoops is prone to multiple SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query.

An attacker may be able to exploit these issues to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well.

Xoops 2.0.16 is vulnerable.

More Information Here : http://www.securityfocus.com/bid/22399/info

SubZero
XOOPSDesign.com

Top


http://www.xoopsdesign.com

"Only two things are infinite, the universe and human stupidity, and I'm not sure about the former."

- Albert Einstein -
subzero_x
Just popping in
Joined:
2006/3/16 16:08
Posts: 24
(Show More) (Show Less)
#2 Posted on: 2007/2/6 9:53 Re: Xoops Multiple Unspecified SQL Injection Vulnerabilities
The core "issue" mentioned in the report was known to XOOPS Core Dev Team and evaluated as not a real vuln.
As for the weblinks module, plz check with the author.

Top


I am contributing to XOOPS at:
* http://sf.net/projects/xoops for development
* http://xoops.org.cn for Chinese local support
phppp
XOOPS Developer
Joined:
2004/1/24 22:40
From Shanghai
Posts: 2184
(Show More) (Show Less)
#3 Posted on: 2007/2/6 11:38 Re: Xoops Multiple Unspecified SQL Injection Vulnerabilities
is this the link module from www.mywebaddons.com ?
where can I find the latest links module for 2.2.x?
thanks for any tips.

Top


http://www.newmag.org/
eric235u
Not too shy to talk
Joined:
2004/12/18 20:55
Posts: 143
(Show More) (Show Less)
#4 Posted on: 2007/2/6 12:14 Re: Xoops Multiple Unspecified SQL Injection Vulnerabilities
I can't help thinking that this thread is unhelpful, being as it is in full public view on the xoops homepage........"Hey, Mr Bad Man, over here and look at this! Now you can attack everyone's xoops pages!"

Two words...... Protector Module.....

Top


John V
Cardiff - UK
JAVesey
Moderator
Joined:
2006/10/19 17:01
From Cardiff - UK
Posts: 2258
(Show More) (Show Less)
#5 Posted on: 2007/2/6 12:21 Re: Xoops Multiple Unspecified SQL Injection Vulnerabilities
The information is also listed on the SecurityFocus site.

Top

davidl2
XOOPS is my life!
Joined:
2003/5/25 21:19
Posts: 4770
(Show More) (Show Less)
#6 Posted on: 2007/2/6 13:00 Re: Xoops Multiple Unspecified SQL Injection Vulnerabilities
Quote:

davidl2 wrote:
The information is also listed on the SecurityFocus site.


True, but I was warm and happy in blissful ignorance until the point that I read it

Top


John V
Cardiff - UK
JAVesey
Moderator
Joined:
2006/10/19 17:01
From Cardiff - UK
Posts: 2258
(Show More) (Show Less)
#7 Posted on: 2007/2/6 13:50 Re: Xoops Multiple Unspecified SQL Injection Vulnerabilities
hi.

Quote:
"I can't help thinking that this thread is unhelpful, being as it is in full public view on the xoops homepage..."


i did not see it. where? do you mean this thread is in full view and don't like talking about exploits or that this issue has already been raised on the home page?

Quote:
Two words...... Protector Module.....


i read a lengthy thread on this and it seemed that the module was a good idea but it was not manditory. xoops core was reasonably secure. please tell me where i'm wrong. a link to further reading would be helpful.

Quote:
The information is also listed on the SecurityFocus site.


i clicked on "solution" and it states, "Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:vuldb@securityfocus.com."

therefore i did not see a resolution to the issue we're discussing at security focus. that's why i asked the question.

Top


http://www.newmag.org/
eric235u
Not too shy to talk
Joined:
2004/12/18 20:55
Posts: 143
(Show More) (Show Less)
#8 Posted on: 2007/2/6 14:09 Re: Xoops Multiple Unspecified SQL Injection Vulnerabilities
Quote:

i read a lengthy thread on this and it seemed that the module was a good idea but it was not manditory. xoops core was reasonably secure. please tell me where i'm wrong. a link to further reading would be helpful.


yes xoops core is reasonably secure. but reasonably is the keyword there.. xoops protector is an essential module if you want more security, and indeed provides other security measures than the core itself provides.

Quote:

i clicked on "solution" and it states, "Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:vuldb@securityfocus.com."

therefore i did not see a resolution to the issue we're discussing at security focus. that's why i asked the question.


there's no solution yet, because the exploit in the core isn't a valid exploit so no solution is necessary.

however the authors of weblinks module, may not even know about the exploit yet in their module, so maybe some1 could slip them a message informing them.. however i don't think the security focus stated the weblinks version number, which in itself might be an older version of that module.. but still the authors need to be aware of the possibility.

Top

vaughan
Friend of XOOPS
Joined:
2005/11/26 16:00
From Derbyshire/UK
Posts: 674
(Show More) (Show Less)
#9 Posted on: 2007/2/6 14:39 Re: Xoops Multiple Unspecified SQL Injection Vulnerabilities
i'm using weblinks 1.1 on xoops 2.2.x by Kazumi Ono. his website no longer is active. i didn't find him on the members module here or on the dev site.

i can't read this:
http://www.hackers.ir/advisories/festival.txt

so i don't know what specific links module he means. i'm shutting my site off from anonymous users until i feel comfortable with the links module.

Top


http://www.newmag.org/
eric235u
Not too shy to talk
Joined:
2004/12/18 20:55
Posts: 143
(Show More) (Show Less)
#10 Posted on: 2007/2/6 16:20 Re: Xoops Multiple Unspecified SQL Injection Vulnerabilities
I too am using weblinks 1.1.... some on 2.0.16 and some on 2.2+ sites. I have removed the submit function from the modules. Only admins can add links and not from the client side, only through administration. Hopefully that plugged the hole.

Top


Magick can never be restrained, but when freely given is thrice regained!
preachur
Just can't stay away
Joined:
2006/2/3 23:37
From Colorado, U.S.A.
Posts: 483
(Show More) (Show Less)

 Top   Previous Topic   Next Topic

1 2 3 »

You can view topic.
You cannot start a new topic.
You cannot reply to posts.
You cannot edit your posts.
You cannot delete your posts.
You cannot add new polls.
You can vote in polls.
You cannot attach files to posts.
You cannot post without approval.

[Advanced Search]