Kolifa Haber Script 1.3 SQL Injection

2011-10-09 / 2011-10-10
Credit: Mr.PaPaRoSSe
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

# Exploit Title: Kolifa Haber Script 1.3 SQL # Date: 08.10.2011 - 20:36 # Author: Mr.PaPaRoSSe # Download Script: http://scripti.org/demo.php?id=97 # Tested On: BackTrack 5 - Windows xp sp3 # Platform: Php >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> Vunl file : show.php Exploit: http://localhost/haber_pro/kategorigoster.php?kat_id=SQL injection Panel: http://haberpro.awardspace.com/haber_pro/admin/admingiris.php >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> # We attempted to work, you can not imagine. >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> # Contact: paparosse.blogspot.com # Greetz: Http://DarkDevilz.in/ >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> ' 3spi0n ~# Black_Umo ALEXTRAX Brs_BaRoN ZyX x-Leader L4NETLY GrayTendriL DARKCOD3R Santiq0 53rh4t PerS Mavi Karanlik Tarxes [And DD'z Family] [DarkDevilz - Defence And Destruction Group'z - TURKEY] >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top