Exploit Classifieds Script - 'rate' SQL Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
13971
Проверка EDB
  1. Пройдено
Автор
L0RD CRUSAD3R
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
N/A
Дата публикации
2010-06-22
Код:
1               ##########################################             1
0               I'm L0rd CrusAd3r member from Inj3ct0r Team            1
1               ##########################################             0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=1
Author: L0rd CrusAd3r aka VSN [[email protected]]
Exploit Title:Classifieds SQL Injection
Vendor url:http://getaphpsite.com
Version:1
Price:20$
Published: 2010-06-22
Greetz to:r0073r (inj3ct0r.com), Sid3^effects, MaYur, MA1201, M4n0j, Sonic Bluehat.
Special Greetz: Topsecure.net, inj3ct0r Team , Andhrahackers.com
Shoutzz:- To all ICW members.
~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~
Description:

Classifieds are an excellent revenue generator that brings sellers and buyers together. With our classifieds site, you can build revenues by offering a service that everyone can use.
The classifieds site is a 100% automated site that allows seller to post ads based on categories. The site comes preprogrammed with PayPal and Stormpay as payment processors using the IPN system for a truly hands free experience.
Sellers create an account and pick a package to post their ads that the admin specifies, which includes choosing from standard ads to featured ads that appear on the main webpage.
This site also includes a rotating banner management system and newsletter that is easily moderated from the admin area.

~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~

Vulnerability:

*SQLi Vulnerability

DEMO URL :

http://server/classifieds/search.php?rate=[sqli]

# 0day n0 m0re #
# L0rd CrusAd3r #
 
Источник
www.exploit-db.com

Похожие темы