iDesign Cms Remote Sql Injection Vulnerability

2011.08.12
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

###### Archieve an Resource About Hacking #### # Exploit Title: iDesign Cms Remote Sql Injection Vulnerability # Author: Netrondoank Aka netron # home Page: http://www.ilmuhacker.org # Forum : http://www.indonesiansecurity.info # Vendor or Software Link: http://www.idesigninc.net/ # Version: N/A # Category:: webapps # Google dork: "Design by: iDesign" # Tested on: Linux Back Track 5 #################################################################### # Proof Of Concept [POC] https://site/view_product.php?id=[Sqli] http://site/ourPortfolio.php?id=[Sqli] http://site/features.php?id=[Sqli] http://site/view_news.php?id=[Sqli] http://site/event.php?id=[Sqli] http://site/view_news.php?id=[Sqli] http://site/store.php?id=[Sqli] http://site/features.php?id=[Sqli] http://site/store.php?id=[Sqli] #################################################################### # Demo http://www.connico.com/ourPortfolio.php?id=%274 http://aacdhq.org/features.php?id=%273 http://www.opheliafordtn.com/view_news.php?id='37 #################################################################### #Lets Join in My crew in http://indonesiansecurity.info. Indonesian security Advisories. ######################################################################################### #Greetz To: Allah swt .free dom For Palestine .Indonesiansecurity.info, 1337day.com packetstormsecurity.org, Exploit-id.com ,securityreason.com ,securityfocus.com ########################################################################################## ############################### Archieve an Resource About Hacking--Ilmuhackerdotorg ####

References:

http://indonesiansecurity.info
http://ilmuhacker.org


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top