[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

E-Store (1.0 & 2.0) <= SQL Injection Vulnerability

Author
Alkeraithe
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-21986
Category
web applications
Date add
06-03-2014
Platform
php
# Exploit Author: Nawaf Alkeraithe
======================================
for "E-store 1.0":
# Google Dork: "Powered by: PD" inurl:"page.php?id"
#Vulnerable page:
http://[target]/page.php?id=[SQL Injection]
======================================
for "E-store 2.0":
# Google Dork: "Powered by: PD" inurl:"news.php?id"
#Vulnerable page:
http://[target]/news.php?id=[SQL Injection]


# demos:
http://www.nourita.com/page.php?id=[Sqli]
http://www.gorgeous.ae/news.php?id=[Sqli]
http://www.henna.ae/news.php?id=[Sqli]



#Contact:
email: Alkeraithe@gmail.com
twitter: https://twitter.com/Alkeraithe

#  0day.today [2024-10-05]  #