header-logo
Suggest Exploit
vendor:
DNNArticle
by:
Sajjad Pourali
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: DNNArticle
Affected Version From: 10.0 and earlier
Affected Version To: 10.0 and earlier
Patch Exists: Yes
Related CWE: CVE-2013-5117
CPE: a:zldnn:dnnarticle
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013

DotNetNuke (DNNArticle Module) SQL Injection Vulnerability

A vulnerability in DotNetNuke (DNNArticle Module) allows an attacker to inject malicious SQL commands into the application. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. The vulnerability is due to insufficient sanitization of user-supplied input in the 'categoryid' parameter of the 'dnnarticlerss.aspx' script. An attacker can exploit this vulnerability to manipulate SQL queries by injecting arbitrary SQL code.

Mitigation:

The vendor has released a patch to address this vulnerability. Users are advised to upgrade to the latest version of DNNArticle.
Source

Exploit-DB raw data:

Title: DotNetNuke (DNNArticle Module) SQL Injection Vulnerability
References: CVE-2013-5117
Discovered by: Sajjad Pourali

Vendor http://www.zldnn.com/ , http://www.dnnarticle.com/‎
Vendor advisory: http://www.zldnn.com/Support/tabid/643/ctl/RecordList/mid/1691/ItemID/2979/Default.aspx (Ticket iD:#2979)
Vendor contact: 2013-8-14

Solution: http://www.zldnn.com/Support/tabid/643/ctl/RecordList/mid/1691/ItemID/2979/Default.aspx (Ticket iD:#2979)
 
Remote: yes
Authentication required: no
User interaction required: no
Impact: High
 
Affected:

 - DNNArticle 10.0 and earlier

---

PoC:

http://server/desktopmodules/dnnarticle/dnnarticlerss.aspx?moduleid=0&categoryid=1+or+1=@@version
 
---
 
 + Sajjad Pourali
 + http://www.securation.com/
 + http://www.cert.um.ac.ir/
 + Contact: sajjad[at]securation.com