[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

NetWorld Portals (storefronts.php) Sql Injection Vulnerability

Author
H-SK33PY
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-13848
Category
web applications
Date add
25-08-2010
Platform
php
==============================================================
NetWorld Portals (storefronts.php) Sql Injection Vulnerability
==============================================================

   010101010101010101010101010101010101010101010101010101010    
   0                                                       0
   1        Iranian Datacoders Security Team 2010          1
   0                                                       0
   010101010101010101010101010101010101010101010101010101010


# Exploit Title: NetWorld Portals (storefronts.php) Sql Injection Vulnerability         
# Date: 25/08/2010                             
# Author: H-SK33PY                      
# Software Link: http://www.networldalliance.com/
# Version :  N/A 
# Platform / Tested on: linux 
# Google Dork : inurl:*.php id & intext:"NetWorld Alliance"
# Category: webapplications
# Code : [SQL injection]

#BUG:#########################################################################

After after use Sting (') and find bug  for injection at sites run SQL Inject :


example : 
http://[PATH]/storefronts.php?sf_id=1[SQL injection]


demo : 

http://www.selfserviceworld.com/storefronts.php?sf_id=63[SQLi]

Good Luck 

#############################################################################
Our Website : http://www.datacoders.ir/

Contact me : h-skeepy@att.net


Special Thanks to : Immortal Boy & Sp|R|T & BigB4NG & hosinn & NIK & uones & all iranian datacoders members

Greetz to : Inj3ct0r.com 

#############################################################################



#  0day.today [2024-11-14]  #