what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

CCBill.com SQL Injection

CCBill.com SQL Injection
Posted Aug 17, 2010
Authored by Ariko-Security

CCBill.com suffers from multiple remote blind SQL injection vulnerabilities.

tags | advisory, remote, vulnerability, sql injection
SHA-256 | 68996150fbbdb71f7b6aa2d4d861e13213826e411394bfef5b4cc03b7f44635e

CCBill.com SQL Injection

Change Mirror Download
  We want to warn you about security vulnerabilities in CCBILL.COM 
Internet billing service.

CCBill is an Internet billing service. Established in 1998, the company
provides third-party billing, or turn-key solutions, for e-Merchants
requiring payments by way of credit card, debit card, or e-check,
European Debit/Direct Pay, and telephone payment.

Since Ccbill is a privately held company little is known about it's
finances however it is estimated that more than a billion dollars per
year in credit card charges are processed through Ccbill in the us and
abroad.

Time Table:
# 20/07/2010 We have found multiple Blind SQL injections.

# 30/07/2010 - Vendor notified. / no response
# 03/08/2010 - Vendor notified. / no response
# 10/08/2010 - Vendor notified. / no response

CCBILL.COM vulnerability:

Multiple blind SQL injections

It's possible to get all customers FULL personal details, server admins
etc...

Also is possible to read any file from ccbill.com and write to this
server too.

JPG sample tables proof:
https://www.ariko-security.com/images/ccbill_proof1.jpg

Credit:
# Discoverd By: MG / Ariko-Security 2010
# https://advisories.ariko-security.com/august/audyt_bezpieczenstwa_719.html

Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close