[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Online Studio (CMS) Zoo2 SQL Injection Vulnerability

Author
cyberlog
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-15078
Category
web applications
Date add
08-12-2010
Platform
php
====================================================
Online Studio (CMS) Zoo2 SQL Injection Vulnerability
====================================================


# Vendor	: http://www.zoo2.com.au/
# prices	: Not Yet:P
# Discovered by : cyberlog
# Site          : Sekuritionline.net
# Channel       : #SekuritiOnline  & #Bajingan [ Now Just My Bot ]

# Dork          : "inurl:"m4h0 w4s h3r3"

# Exploit       : [site]/news.html?news_id= [SQL Injection]
		  [site]/Whats_New.html?news_id= [SQL Injection]
		  [site]/eventdisplay.php?id= [sql injection ]

# Backd0r can Upload from admin panel :( [ ext.php allowed to panel admin ]

# Thanks        : GOD,r0073r,adhietslank, k1n9k0ng, cr4wl3r,cah_gemblunkz,
jayoes,thesims,setiawan,irvian,EA_Angel,BlueSpy,SoEy,A-technique,Jantap,KiLL,blindboy,sukam,pencopet_cinta, pomponk,
SarifJedul,wiro_gendenk,Letjen,ridho_bugs,Ryan_Kabrutz,aurel666,Inof,dbanie, GuA_NinOx, ant0_h@ck, marlon_inside

# special to Mama Sri Rahayu, Member& Staff Sekuritonline,Inj3ct0r, H4ckb0x,JatimCr3w,ManadoCoding, Bajingan Crew,
# C0li a.k.a antisecurity [ pinjem script perl-na ] 
# Hiroyuki Doni thanks to create New design SO T-shirt P
# Inj3ct0r Now Brothers with Sekuritionline
# inj3ct0r change to http://1337db.com/
# I'm n't hacker just lik3 security system :)
# just for education  :)


####################################################

# Demo offline:
# http://localhost/news.html?news_id= [SQL Injection]

####################################################



#  0day.today [2024-09-28]  #