[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Dataville CMS (produtos.php) SQL Injection Vulnerability

Author
H-SK33PY
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-14029
Category
web applications
Date add
08-09-2010
Platform
php
========================================================
Dataville CMS (produtos.php) SQL Injection Vulnerability
========================================================

010101010101010101010101010101010101010101010101010101010    
   0                                                       0
   1        Iranian Datacoders Security Team 2010          1
   0                                                       0
   010101010101010101010101010101010101010101010101010101010


# Exploit Title: Dataville CMS SQL Injection Vulnerability            
# Date: 07/09/2010                             
# Author: H-SK33PY                      
# Software Link: http://www.dataville.com.br/
# Version: N/A
# Google dork :  inurl:id= & intext:"Desenvolvido por Dataville" 
# Platform / Tested on: linux
# Category: webapplications
# Code : [SQLi]


#BUG:#########################################################################

After after use Sting (') and find bug  for injection at sites run SQL Inject :


example : 
http://[PATH]/produtos.php?catID=1[SQL injection]


demo : 

http://www.emporiodolar.com.br/produtos.php?catID=1[sql injection]


Good Luck 

#############################################################################
Our Website : http://www.datacoders.ir/

Contact me : h-skeepy@att.net



#  0day.today [2024-11-16]  #