Campaign Enterprise 11.0.421 – SQL Injection

  • 作者: Craig Freyman
    日期: 2012-01-30
  • 类别:
  • 来源:
  • ########################################################################################
    #Exploit Title: Campaign Enterprise 11.0.421 SQLi Vulnerability
    #Author: Craig Freyman (@cd1zz)
    #Date Discovered: 12/12/2011
    #Vendor Site:
    #Vendor Notified: 1/19/2012 
    #Vendor Fixed: 1/30/2012 (Version 11.0.512)
    #Description: The SID parameter in a POST is vulnerable to a boolean based blind SQLi. 
    #You must be authenticated to access this parameter. The default database for Campaign
    #Enterprise is MS Access.
    #Proof of Concept
    POST /Command HTTP/1.1