Headlines
Published On:Saturday, 5 October 2013
Posted by Unknown

WHMCS 5.2.7 SQLI INJECTION


WHMCS 5.2.7 SQLI INJECTION

So, Friends and Enemies :p here is the Lastest Vulnerability Leaked in Black Hackers Market for WHMCS

Vulnerability Effects:

/includes/dbfunctions.php:
<?php
function update_query($table, $array, $where) {
#[...]
if (substr($value, 0, 11) == 'AES_ENCRYPT') {
$query .= $value.',';
continue;
}
#[...]
$result = mysql_query($query, $whmcsmysql);
}
?>



and download exploit from following link

Exploit in python:

http://www.mediafire.com/download/bep724fwr8t4scl/whmcs.py


Exploit in php:

http://www.mediafire.com/download/5y10bzblp9bo92q/cyberaon(2).php

Register a new user on a target WHMCS install (/register.php)
 
and edit the exploit with site name, email and password.

Have Fun Guys!!!!

About the Author

Posted by Unknown on 23:46. Filed under , , . You can follow any responses to this entry through the RSS 2.0. Feel free to leave a response

By Unknown on 23:46. Filed under , , . Follow any responses to the RSS 2.0. Leave a response

2 comments for "WHMCS 5.2.7 SQLI INJECTION"

  1. The php version is not workin.

  2. Naa The PyTHon VeRsIon HAs TrAceS of VirUs!! :P :D :*

Leave a reply

Blogumulus by Roy Tanck and Amanda Fazani

Pages

Powered by Blogger.

Labels

Labels

Blogger news

Labels

Blogger templates

Popular Posts