Mambo 4.x – ‘Zorder’ SQL Injection

  • 作者: KraL BeNiM
    日期: 2011-11-13
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/18110/
  • *####################################################################
    [+] Exploit Title : CMS 4.x.x Zorder (SQL Injection Vul)
    [+] Author : Kr4L BeNiM
    [+] Contact : www.facebook.com/kr4l.hacker
    [+] Date : November 13, 2011
    [+] Software Link:http://mambo-developer.org
    [+] Category: Web Apps
    ####################################################################
    
    Vulnerability:
    
    *SQL injection Vulnerability*
    
    [#]Exploit : -
    
    The "zorder" parameter was not properly sanitized upon submission to
    the administrator/index2.php url, which allows attacker to conduct
    SQL Injection attack.
    
    
    [#] Explaination : -
    
    http://target.com/mambo/administrator/index2.php?limit=10&order[]=11&boxchecked=0&toggle=on&search=sqli&task=&limitstart=0&cid[]=on&zorder=
    (SQL Inj Codes)
    
    ####################################################################
    [+] Greets : Likuid Sky, Hax.Root, S.O.G, DjArs HaXoR, KiLLerMiNd, CyberLeeTs
    ####################################################################