Dashing Times SQL Injection

2014.08.22
Credit: 3spi0n
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

################################################################################## dashing times cms scripts, sql injection vulnerability. products page: http://www.dashingtimes.in/portfolio/ author(pentester): 3spi0n on social: twitter.com/eyyamgudeer ################################################################################## [description] i found vulnerability all cms scripts of dashingtimes web design. [some weak websites] [+] (categories.php, catid param) >>> http://gayatrifashions.com/categories.php?catId='24 [+] (index.php, id param) >>> http://skglassmachines.com/index.php?id='2 >>> http://mithasgroup.net/overview/index.php?id='24 [+] (page.php, id param) >>> http://igsecurityindia.com/page.php?id='2 >>> http://rainbow-group.co.in/page.php?id='2 >>> http://sshousekeepingservices.com/page.php?id='10 ################################################################################## and greetings, grayhats and janissaries. "since 2008, espion." ##################################################################################


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top