Advertisement
AndrewHaxalot

NoticeBoardPro v1.X SQL Injection Vulnerability

Dec 29th, 2013
86
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.46 KB | None | 0 0
  1. [+] Author: TUNISIAN CYBER
  2. [+] Exploit Title: NoticeBoardPro v1.X SQL Injection vulnerability
  3. [+] Date: 27-12-2013
  4. [+] Category: WebApp
  5. [+] Google Dork: n/a
  6. [+] Tested on: KaliLinux
  7. [+] Vendor: http://www.noticeboardpro.com/
  8.  
  9.  
  10. ########################################################################################
  11.  
  12. +Description:
  13. NoticeBoardPro is an online, web-based, notice / bulletin board system that acts as a market place and lets you advertise.
  14.  
  15. +Exploit:
  16. NoticeBoardPro Suffers from an SQL Injection vulnerability.
  17.  
  18. File(s): deleteItem3.php
  19. deleteItem2.php
  20. deleteItem1.php
  21. Parameter:noticeID
  22. userID
  23. [PHP]
  24. $noticeID=$_GET['noticeID'];
  25. $userID=$_GET['userID'];
  26.  
  27. mysql_connect("$hostName", "$dbusername", "$dbpassword");
  28.  
  29. $result1 = mysql_query("SELECT * FROM $databaseName.notice_nbp where $databaseName.notice_nbp.noticeID = '$noticeID' and $databaseName.notice_nbp.userID = '$userID'");
  30.  
  31. $result = mysql_query("DELETE FROM $databaseName.notice_nbp where $databaseName.notice_nbp.noticeID = '$noticeID' and $databaseName.notice_nbp.userID = '$userID'");
  32. [PHP]
  33.  
  34. P.O.C:
  35. http://127.0.0.1/NoticeBoardPro/deleteItem3.php?noticeID=&userID=[SQL]
  36. ./3nD
  37. ########################################################################################
  38. Greets to: XMaX-tn, N43il HacK3r, XtechSEt
  39. Sec4Ever Members:
  40. DamaneDz
  41. UzunDz
  42. GEOIX
  43. ########################################################################################
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement