GulfTech Computers - Professional Computer Services  
Additional Links
-> Dicussion Forum
-> Encryption Tools
-> Information Tools
-> Net Info Tools
-> Latest Advisories
-> Latest Vulns
-> Latest Win Software
-> Latest Nix Software
-> Security News
-> Security Press
Recent News

GulfTech Computers strives to beat the price(s) of any other business around. Check with us first as it just may save you some time and money. And who doesn't want to save money? Please contact us with any questions or inquiries.

Latest GulfTech Releases

SubScan v1.2 Scans a domain for DNS records and SubDomains. Very stealthy, and can be used to find many hosts not on the public netblock. A very interesting tool to say the least. Works on both Nix and Windows based systems. Get it now!

Download SubScan v1.2

Search GulfTech
You can use the form below to search our site. Just enter the keyword or keywords to search.
Latest Advisories
SCO Security Advisory - OpenServer 5.0.6 OpenServer 5.0.7 : uudecode does not check for symlink or pipe (SCOSA-2004.7)
SCO Security Advisory - OpenServer 5.0.6 OpenServer 5.0.7 : OpenSSL Multiple Vulnerabilities (SCOSA-2004.10)
SCO Security Advisory - OpenServer 5.0.6 OpenServer 5.0.7 : Xsco contains a buffer overflow that could be exploited to gain root privileges (SCOSA-2004.3)
SCO Security Advisory - UnixWare 7.1.3 Open UNIX 8.0.0 : Xsco contains a buffer overflow that could be exploited to gain root privileges. (SCOSA-2004.2)
Microsoft Security Bulletin Re-release, August 2004
Latest Vulnerabilities
OpenFTPD Format String Vulnerability
Fusion News Unauthorized Account Addition Vulnerability
Jaws 0.4 Authentication Bypass Vulnerability
DansGuardian Hex Encoding URL Banned Extension Filter Bypass Vulnerability
LostBook v1.1 Javascript Execution Vulnerability
Latest Security News
Anti-spam spamvertisers agree to quit
Black Hat day 2 sounds security alarm
VPNs (Virtual Private Nightmares)
HNS Newsletter issue 224 has been released
Long-awaited IE patch (finally) arrives















Invision Gallery SQL Injection Vulnerabilities
March 22, 2022


Vendor : Invision Power Services
URL : http://www.invisiongallery.com
Version : Invision Gallery 1.0.1
Risk : SQL Injection Vulnerabilities
BID : http://www.securityfocus.com/bid/9944


Description:
Invision Gallery is a fully featured, powerful gallery system that is easy and fun to use! It plugs right into your existing Invision Power Board to create a seamless browsing experience for the users of your forum. We've taken many of the most popular feature requests from our customers and integrated them into this product.


SQL Injection Vulnerabilities:
Invision Gallery seems to come up very short concerning validation of user supplied input. It is vulnerable to a number of SQL Injection vulnerabilities. Also, because Invision Gallery is integrated into Invision power Board it is VERY much possible for an attacker to use the vulnerabilities in Invision Gallery to affect the Invision Power Board which it resides on. Most of the non validated input that allow for the injections take place right in the middle of a WHERE statement making them that much easier to exploit. Lets look at an example error.

-----[ Start Error ]---------------------------------------------
mySQL query error: SELECT * FROM ibf_gallery_categories WHERE 
id=[Evil_Query]
mySQL error: You have an error in your SQL syntax.  Check the manual 
that corresponds to your MySQL server version for the right syntax to 
use near '[Evil_Query]' at line 1
mySQL error code: 
Date: Sunday 21st of March 2004 11:28:18 AM
-----[ /Ends Error ]---------------------------------------------

As we can see from this it would be of little difficulty for any attacker to execute arbitrary requests. For example pulling the admin hash and/or possibly taking admin control over an affected Invision Gallery or Invision Power Board installation. Here are some example urls that could be exploited by an attacker.

index.php?act=module&module;=gallery&cmd;=si&img;=[SQL]
index.php?act=module&module;=gallery&cmd;=editimg&img;=[SQL]
index.php?act=module&module;=gallery&cmd;=ecard&img;=[SQL]
index.php?act=module&module;=gallery&cmd;=moveimg&img;=[SQL]
index.php?act=module&module;=gallery&cmd;=delimg&img;=[SQL]
index.php?act=module&module;=gallery&cmd;=post&cat;=[SQL]
index.php?act=module&module;=gallery&cmd;=sc&op;=user&sort;_key=[SQL]
index.php?act=module&module;=gallery&cmd;=sc&op;=user&sort;_key=dateℴ_key=[SQL]
index.php?act=module&module;=gallery&cmd;=favs&op;=add&img;=[SQL]
index.php?act=module&module;=gallery&cmd;=slideshow&cat;=[SQL]
index.php?act=module&module;=gallery&cmd;=user&user;=[SQL]&op;=view_album&album;=1
index.php?act=module&module;=gallery&cmd;=user&user;=[SQL]
index.php?act=module&module;=gallery&cmd;=user&user;=1&op;=view_album&album;=[SQL]

Some of these are easier to exploit than others obviously, but the large number of SQL Injection possibilities definitely makes it that much easier for an attacker to get results from these issues.


Solution:
The Invision Power Services team were contacted immediately and hopefully a fix will be available soon since this is an application that cost users money to use.


Credits:
Credits go to JeiAr of the GulfTech Security Research Team.






© Copyright 2002 - GulfTech Computers, All Rights Reserved
Contact GulfTech Computers