Need help with this (XXE and\or SQLi) 03-02-2015, 01:10 PM
#1
Basically, me and a friend of mine were messing with a huuuge mobile provider yesterday, and we reached a dead end.
We found several things:
- Most types of XSS (not very useful yet)
- An SQLi which we can't use, because either addslashes or magic_quotes are working
- A potential XXE
Here are some details now.
The potential XXE:
The failed SQLi:
Anyone that wants to help me, please, post here or PM me ^^
We found several things:
- Most types of XSS (not very useful yet)
- An SQLi which we can't use, because either addslashes or magic_quotes are working
- A potential XXE
Here are some details now.
The potential XXE:
Spoiler:
The site has a cart system (summercart I think), where you can add stuff to your cart or wishlist and then buy it when you want.
The cart itself uses XML in a cookie to store the items.
![[Image: 90ba5da831.png]](http://puu.sh/gjb0K/90ba5da831.png)
I tried changing it, but on every request, it updates back to that.
The cart itself uses XML in a cookie to store the items.
![[Image: 90ba5da831.png]](http://puu.sh/gjb0K/90ba5da831.png)
I tried changing it, but on every request, it updates back to that.
The failed SQLi:
Spoiler:
You can add addresses on the site.
It doesn't filter html, so there are several persistent XSS' on there, but that's not the main thing.
It stores everything in a database. Here's the POST request.
And the error it produces:
It doesn't filter html, so there are several persistent XSS' on there, but that's not the main thing.
It stores everything in a database. Here's the POST request.
Code:
CountryID=34&StateID='&OriginalCustomerState=&CustomerAddressLine1=асд&CustomerAddressCity=дсадtukaaaa&CityID=&CustomerAddressLine2=&CustomerAddressZip=33&action=dmExecCreate&CustomerAddressIsDefaultCard=And the error it produces:
Code:
Error appeared. Record creation failed: Cannot add or update a child row: a foreign key constraint fails (`mtel_eshop`.`CustomerAddresses`, CONSTRAINT `FK_CustomerAddresses_StateID` FOREIGN KEY (`StateID`) REFERENCES `States` (`StateID`) ON UPDATE CASCADE) (INSERT INTO CustomerAddresses(CustomerAddressID,CustomerID,CustomerAddressLine1,CustomerAddressLine2,CustomerAddressCity,CityID,CustomerAddressZip,CountryID,StateID,CustomerAddressIsDefaultBilling,CustomerAddressIsDefaultShipping,CustomerAddressIsDefaultContact,CustomerAddressIsDefaultCard) VALUES("","146062","0A4","","4A04tukaaaa",NULL,"33","34","\'",FALSE,FALSE,FALSE,FALSE))Anyone that wants to help me, please, post here or PM me ^^


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)

















![[Image: F4Z9Dqw.png]](https://i.imgur.com/F4Z9Dqw.png)



