vendor:
ADN Forum
by:
StAkeR
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: ADN Forum
Affected Version From: 1.0b
Affected Version To: 1.0b
Patch Exists: YES
Related CWE: N/A
CPE: a:adn_forum:adn_forum:1.0b
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
ADN Forum <= 1.0b Blind SQL Injection Exploit
This exploit is used to gain access to the MD5 hash of the password of the user with ID 1 in the ADN Forum version 1.0b. It uses a blind SQL injection vulnerability to achieve this. The exploit is written in Perl and uses the LWP::UserAgent module to send requests to the server. It then iterates through a list of characters and sends requests with the ascii value of the character in the query. If the response is successful, it adds the character to the MD5 hash and moves on to the next character.
Mitigation:
The best way to mitigate this vulnerability is to upgrade to a version of ADN Forum that is not affected by this exploit.