GBook SQL injection vulnerability? Someone's been drunk...

Dr. GBooky is here to help you with your guestbook problems ...
Post Reply
Klemen
Site Admin
Posts: 10113
Joined: Fri Feb 11, 2005 4:04 pm

GBook SQL injection vulnerability? Someone's been drunk...

Post by Klemen »

Just thought I would share an anecdote with you.

It came to my attention that numerous reports have been spreading around the Web about a SQL injection vulnerability in GBook from PHPjunkyard, such as
##PHP junkyard Guestbook v1.6 (mes_id) Sql Injection Vuln.
##Yazar: Bgh7
##
##Turk Bilisim Gucleri / Ihlilal Hatti
##
##ByBgh7[a]Msn.Com
##
##Bgh7.Blogspot.Com
##
##Bug: Sql Injection
##
##İndir/Download: http://www.phpjunkyard.com/php-guestbook-script.php
##
##Not: $20.00 USD

Sql: site/guestbook.php?mes_id=-99999 UNION SELECT
0,1,2,concat_ws(user,0x3a,pass,0x3a,mail),4,5,6,7,8,9,10,11,12 FROM
jyuser--
The funny part is - GBook doesn't use a SQL database at all so SQL injection vulnerabilities are not even remotely possible. Looks like the script kiddie who calls himself "Bgh7" has been drunk while testing this...

Anyway, just thought I'd let you all know before someone gets a panic attack.
Klemen, creator of HESK and PHPJunkyardWas this helpful? You can buy me a drink here Image

Image You should follow me on Twitter here

Help desk software | Cloud help desk | Guestbook | Link manager | Click counter | more PHP Scripts ...

Also browse for php hosting companies, read php books, find php resources and use webmaster tools
DC
Posts: 138
Joined: Sun Dec 09, 2007 9:28 am

Post by DC »

That is funny, I was thinking the same thing when I was reading the heading I was like what? SQL thats like the ignaramouses who try and breach my scripts with MSQL exploits what are these guys drinking? Klem are you sure you didn't buy them the beer as they must really be loaded ...

DC
To Code Or Not To Code That Is The Question?

Was my post of any help to you? if so please do [url=http://www.clickcraft.net/slice_donations.php][b]Buy Me A Slice[/b][/url] ...
Post Reply