Orange Dice Solutions CMS SQL Injection

2016.11.09
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

|[+] Exploit Title: Orange Dice Solutions CMS SQL Injection |[+] |[+] Exploit Author: M4ni4c |[+] |[+] Team Name: Azerbaijan Cyber Army |[+] |[+] Google Dork: intext:Powered By Orange Dice Solutions inurl:.php?id= |[+] |[+] Date: 09.11.2016 |[+] |--------------------------------------------------------------| |[+] Admin panel: /admin/ |[+] |[+] Examples: |[+] |[+] http://www.almarqabspareparts.com/product.php?id=20 |[+] |[+] http://www.focussecuritysystem.com/album.php?id=1 |[+] |[+] http://www.vudpecker.com/category.php?id=1 |[+] |[+] Qarabag Bizimdir, Bizim Olacaq |[+] |[+] Thanks: KroNiqs, Niko, Riko, Dado |[+] And Thanks My Friends: F3D4I & AlpArslan Beyy |[+] Special Thanks: CXSECURITY.COM Team's Members


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top