Chloe SQL INJECTION VULNERABILITY

Published
Credit
Risk
2017.05.14
Mohammad Babaee
Medium
CWE
CVE
Local
Remote
CWE-89
N/A
No
Yes
Dork: intext:"Web design by Chloe Design"

Exploit Title : Chloe SQL INJECTION VULNERABILITY
Google Dork : intext:"Web design by Chloe Design"
Date : 14/05/2017
Exploit Author : Mohammad Babaee
Vendor Homepage : http://www.pave.tw/
Software Link : http://www.pave.tw/
Version : 2.0
Tested on : Windows10 , Firefox

################################################################


Proof of concept : Elevel SQL INJECTION

1 - Search this Google Dork : intext:"Web design by Chloe Design"
2 - Find Websites With SQL INJECTION BUG
3 - Open One of them ( Random )
4 - Attention to end of URL , with number value Like: ( .php?id=836 )
5 - Start Your injection Attack
6 - The End , Enjoy Of Hacking ...!

DEMO :

http://www.as-tw.com.tw/news_more.php?Id=24' [SQL INJECTION VULNERABILITY]

http://www.tw-tvma.org/publishing.php?sn=4' [SQL INJECTION VULNERABILITY]

# Discovered by : Mohammad Babaee

# Special thanks to : Behrouz Mansoori


See this note in RAW Version

 
Bugtraq RSS
Bugtraq
 
CVE RSS
CVEMAP
 
REDDIT
REDDIT
 
DIGG
DIGG
 
LinkedIn
LinkedIn


Copyright 2017, cxsecurity.com