exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Seo Panel 2.2.0 SQL Injection

Seo Panel 2.2.0 SQL Injection
Posted Feb 16, 2011
Authored by High-Tech Bridge SA | Site htbridge.com

Seo Panel version 2.2.0 suffers from multiple remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
SHA-256 | 4aeaba7c6b82354b1bb4d94a7be9784d7bdf4c44c32481a7e292675ea6477aa8

Seo Panel 2.2.0 SQL Injection

Change Mirror Download
====================================
Vulnerability ID: HTB22825
Reference: http://www.htbridge.ch/advisory/sql_injection_in_seo_panel_2.html
Product: Seo Panel
Vendor: http://www.seopanel.in/ ( http://www.seopanel.in/ )
Vulnerable Version: 2.2.0
Vendor Notification: 01 February 2011
Vulnerability Type: SQL Injection
Risk level: High
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/)

Vulnerability Details:
The vulnerability exists due to failure in the "/reports.php" script to properly sanitize user-supplied input in "website_id" variable.
Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.

The following PoC is available:


POST /reports.php HTTP/1.1

website_id=-1%20union%20select%201,version(),3,4,5,6,7,8,9%20--%20&sec=reportsum


====================================
Vulnerability ID: HTB22824
Reference: http://www.htbridge.ch/advisory/sql_injection_in_seo_panel_1.html
Product: Seo Panel
Vendor: http://www.seopanel.in/ ( http://www.seopanel.in/ )
Vulnerable Version: 2.2.0
Vendor Notification: 01 February 2011
Vulnerability Type: SQL Injection
Risk level: High
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/)

Vulnerability Details:
The vulnerability exists due to failure in the "/websites.php" script to properly sanitize user-supplied input in "url" variable.
Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.

The following PoC is available:


POST /websites.php HTTP/1.1

sec=create&name=123&url=http%3A%2F%2F123'%2Cversion()%2C1%2C1%2C2%2C1)%20--%20&title=1&description=1&keywords=1


====================================
Vulnerability ID: HTB22823
Reference: http://www.htbridge.ch/advisory/sql_injection_in_seo_panel.html
Product: Seo Panel
Vendor: http://www.seopanel.in/ ( http://www.seopanel.in/ )
Vulnerable Version: 2.2.0
Vendor Notification: 01 February 2011
Vulnerability Type: SQL Injection
Risk level: High
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/)

Vulnerability Details:
The vulnerability exists due to failure in the "/index.php" script to properly sanitize user-supplied input in "lang_code" variable.
Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.

The following PoC is available:


http://[host]/index.php?&lang_code=1%27SQL_CODE_HERE


Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    18 Files
  • 14
    Aug 14th
    50 Files
  • 15
    Aug 15th
    33 Files
  • 16
    Aug 16th
    23 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    43 Files
  • 20
    Aug 20th
    29 Files
  • 21
    Aug 21st
    42 Files
  • 22
    Aug 22nd
    26 Files
  • 23
    Aug 23rd
    25 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close