<?xml version='1.0' encoding='UTF-8'?>
<rss version='2.0'>
	<channel>
		<title>cotonti.com : Search SQL injection</title>
		<link>https://www.cotonti.com</link>
		<description>Последние сообщения в теме</description>
		<generator>Cotonti</generator>
		<language>en</language>
		<pubDate>Wed, 15 Apr 2026 16:26:43 -0000</pubDate>

		<item>
			<title>GHengeveld</title>
			<description><![CDATA[<p>
	Actually this isn't really a problem. Production sites should have error reporting disabled, so it won't show the SQL error or backtrace. Nevertheless its good to report these things.</p>
]]></description>
			<pubDate>чт, 22 сен 2011 17:18:24 -0000</pubDate>
			<link><![CDATA[https://www.cotonti.com/ru/forums?m=posts&q=6522&d=0#post30803]]></link>
		</item>
		<item>
			<title>badc0re</title>
			<description><![CDATA[<p>
	No problem man.</p>
]]></description>
			<pubDate>ср, 21 сен 2011 13:07:26 -0000</pubDate>
			<link><![CDATA[https://www.cotonti.com/ru/forums?m=posts&q=6522&d=0#post30792]]></link>
		</item>
		<item>
			<title>Trustmaster</title>
			<description><![CDATA[<p>
	It's a little harm anyways and it'll be fixed in 0.9.5, thank you once again for the report!</p>
]]></description>
			<pubDate>ср, 21 сен 2011 11:45:08 -0000</pubDate>
			<link><![CDATA[https://www.cotonti.com/ru/forums?m=posts&q=6522&d=0#post30791]]></link>
		</item>
		<item>
			<title>badc0re</title>
			<description><![CDATA[<p>
	Take a look at </p>
<pre class="brush:java;">
#0  cot_diefatal(SQL error 42S22: Column not found: 1054 Unknown column 'ft_updatedINJECTED_PARAMINJECTED_PARAM' in 'order clause')

And

GROUP BY t.ft_id ORDER BY ft_updatedINJECTED_PARAMINJECTED_PARAM ASC

It looks like sql injection to me.</pre>
]]></description>
			<pubDate>ср, 21 сен 2011 10:00:10 -0000</pubDate>
			<link><![CDATA[https://www.cotonti.com/ru/forums?m=posts&q=6522&d=0#post30790]]></link>
		</item>
		<item>
			<title>Trustmaster</title>
			<description><![CDATA[<p>
	It is more path disclosure than SQL injection, but thank you for the report!</p>
]]></description>
			<pubDate>ср, 21 сен 2011 07:34:15 -0000</pubDate>
			<link><![CDATA[https://www.cotonti.com/ru/forums?m=posts&q=6522&d=0#post30787]]></link>
		</item>
		<item>
			<title>badc0re</title>
			<description><![CDATA[<blockquote>
	<a href="https://www.cotonti.com/forums.php?m=posts&amp;p=30749%2330749">#30749</a> <strong>esclkm: </strong><br /><p>
		but where was injection??? this field has ALP filter - which filter only [A-Za-z0-z_] try to inject</p>
	<p>
		 </p>
</blockquote>
<p>
	<strong>Added 2 minutes later:</strong></p>
<p>
	Well the search is vulnerable. Try it by yourself.</p>
<p>
	Maybe it's not exploitable but it could lead to information extraction.</p>
]]></description>
			<pubDate>вс, 18 сен 2011 21:36:23 -0000</pubDate>
			<link><![CDATA[https://www.cotonti.com/ru/forums?m=posts&q=6522&d=0#post30752]]></link>
		</item>
		<item>
			<title>esclkm</title>
			<description><![CDATA[<p>
	but where was injection??? this field has ALP filter - which filter only [A-Za-z0-z_] try to inject</p>
]]></description>
			<pubDate>вс, 18 сен 2011 19:36:40 -0000</pubDate>
			<link><![CDATA[https://www.cotonti.com/ru/forums?m=posts&q=6522&d=0#post30749]]></link>
		</item>
		<item>
			<title>badc0re</title>
			<description><![CDATA[<p>
	Hi i want to report a SQL injection.</p>
<p>
	The request:</p>
<pre class="brush:java;">
GET http://localhost/cotonti/index.php?e=search&amp;sq=%5C'%5C'%5C'%5C'%5C'&amp;rs%5Bsetlimit%5D=0&amp;rs%5Bday%5D=18&amp;rs%5Bmonth%5D=9&amp;rs%5Byear%5D=2010&amp;rs%5Bday%5D=18&amp;rs%5Bmonth%5D=9&amp;rs%5Byear%5D=2011&amp;rs%5Bsetuser%5D=&amp;rs%5Bpagsub%5D%5B%5D=all&amp;rs%5Bpagtitle%5D=1&amp;rs%5Bpagdesc%5D=1&amp;rs%5Bpagtext%5D=1&amp;rs%5Bpagsort%5D=date&amp;rs%5Bpagsort2%5D=ASC&amp;rs%5Bfrmsub%5D%5B%5D=all&amp;rs%5Bfrmtitle%5D=1&amp;rs%5Bfrmtext%5D=1&amp;rs%5Bfrmsort%5D=updated'INJECTED_PARAM'INJECTED_PARAM&amp;rs%5Bfrmsort2%5D=ASC HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:6.0.2) Gecko/20100101 Firefox/6.0.2
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Proxy-Connection: keep-alive
Referer: http://localhost/cotonti/index.php?e=search&amp;sq=%27%27%27%27%27&amp;rs[setlimit]=0&amp;rs[day]=18&amp;rs[month]=9&amp;rs[year]=2010%271%27&amp;rs[day]=18&amp;rs[month]=9&amp;rs[year]=2011&amp;rs[setuser]=&amp;rs[pagsub][]=all&amp;rs[pagtitle]=1&amp;rs[pagdesc]=1&amp;rs[pagtext]=1&amp;rs[pagsort]=date&amp;rs[pagsort2]=ASC&amp;rs[frmsub][]=all&amp;rs[frmtitle]=1&amp;rs[frmtext]=1&amp;rs[frmsort]=updated&amp;rs[frmsort2]=ASC
Cookie: PHPSESSID=bnq658i0omp7t3u654i85llj51
Content-length: 0</pre>
<div>
	 </div>
<div>
	 </div>
<div>
	Result:</div>
<p>
	2011-09-18 19:03</p>
<pre class="brush:java;">
Fatal error: SQL error 42S22: Column not found: 1054 Unknown column 'ft_updatedINJECTED_PARAMINJECTED_PARAM' in 'order clause'

#0  cot_diefatal(SQL error 42S22: Column not found: 1054 Unknown column 'ft_updatedINJECTED_PARAMINJECTED_PARAM' in 'order clause') called at [D:\xampp2\htdocs\cotonti\system\database.php:436]
#1  CotDB-&gt;query(SELECT SQL_CALC_FOUND_ROWS p.*, t.*
			 	FROM cot_forum_posts AS p, cot_forum_topics AS t
				WHERE t.ft_cat IN ('pub','general','offtopic') AND (t.ft_title LIKE '%\\\\\\\'\\\\\\\'\\\\\\\'\\\\\\\'\\\\\\\'%' OR p.fp_text LIKE '%\\\\\\\'\\\\\\\'\\\\\\\'\\\\\\\'\\\\\\\'%') AND p.fp_topicid = t.ft_id
				GROUP BY t.ft_id ORDER BY ft_updatedINJECTED_PARAMINJECTED_PARAM ASC
				LIMIT 0, 50) called at [D:\xampp2\htdocs\cotonti\plugins\search\search.php:367]
#2  include(D:\xampp2\htdocs\cotonti\plugins\search\search.php) called at [D:\xampp2\htdocs\cotonti\system\plugin.php:94]
#3  require_once(D:\xampp2\htdocs\cotonti\system\plugin.php) called at [D:\xampp2\htdocs\cotonti\index.php:92]</pre>
<pre>

On version 9.4</pre>
]]></description>
			<pubDate>вс, 18 сен 2011 19:14:03 -0000</pubDate>
			<link><![CDATA[https://www.cotonti.com/ru/forums?m=posts&q=6522&d=0#post30747]]></link>
		</item>
	</channel>
</rss>