Published On:Saturday, 5 October 2013
Posted by Unknown
WHMCS 5.2.7 SQLI INJECTION
WHMCS 5.2.7 SQLI INJECTION
Vulnerability Effects:
/includes/dbfunctions.php:
<?php
function update_query($table, $array, $where) {
#[...]
if (substr($value, 0, 11) == 'AES_ENCRYPT') {
$query .= $value.',';
continue;
}
#[...]
$result = mysql_query($query, $whmcsmysql);
}
?>
and download exploit from following link
Exploit in python:
http://www.mediafire.com/download/bep724fwr8t4scl/whmcs.py
Exploit in php:
http://www.mediafire.com/download/5y10bzblp9bo92q/cyberaon(2).php
Register a new user on a target WHMCS install (/register.php)
and edit the exploit with site name, email and password.
Have Fun Guys!!!!


The php version is not workin.
Naa The PyTHon VeRsIon HAs TrAceS of VirUs!! :P :D :*