Description
HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate database queries by injecting SQL code through the 'id' parameter. An unauthenticated attacker can exploit the desa module (module=desa&act=hapus), while authenticated users can exploit the pengurus, fasilitas, and kelompok modules (for example act=print, act=editpengurus, act=editfasilitas, and act=editkelompok). Successful exploitation allows extraction of sensitive database information including the current user, database name, and DBMS version.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
Ihsan Sencan
References
www.exploit-db.com/exploits/45588 (ExploitDB-45588)
www.sitejo.id (Official Product Homepage)
sourceforge.net/projects/hape-pkh/files/latest/download (Product Reference)
www.vulncheck.com/...ion-via-id-parameter-in-admin-media-php (VulnCheck Advisory: HaPe PKH 1.1 SQL Injection via id Parameter in admin/media.php)