Restaurantbiller SQL Injection / Shell Upload

2015.01.28
Credit: R3vanBastard
Risk: High
Local: No
Remote: Yes
CVE: N/A

=================================================================================== [+] TITLE : Restaurantbiller Multiple Vulnerabilities [+] VENDOR : http://www.demo.restaurantbiller.com/ [+] VERSION : - [+] AUTHOR : R3vanBastard [+] TESTED ON : Windows [+] DORK : "Powered by Restaurant Biller" inurl:/index.php?act=category&cid= [+] YM : revan_blezinsky[at]yahoo.com [+] Exploit : Not for sale :D free!!!!! ==================================================================================== DEMO: http://piccolos.ky//index.php?act=category&cid= [SQLi] Login into admin panel then upload your backdoor (easy?) Shell: http://piccolos.ky/UserFiles/Image/product_photos/54c7f27f03a59.shell.php Note: You will get sensitive data in the database like payment information :D ===================================================================================== Thanks to: My PC | Jogjamakeup.com | Mainhack |VOP CREW| Jack | rdnc.or.id | BoBy a.k.a c0li(yg botnya di gangbang) =====================================================================================


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top