Mata-i grasa _|_
RST  

Go Back   RST > >> 1337 Zone << > Exploituri si POCs

Exploituri si POCs Cele mai noi exploituri

Reply
Old 03-16-2010, 12:11 AM   #1 (permalink)
Registered user
Bautor de gin
 
Join Date: Jan 2010
Posts: 248
Rep Power: 1
ANdreicj se balangane pe drum
ANdreicj is offline

Default PHP Classifieds v7.5 Blind SQL Injection Vulnerability


hotel regim hotelier
hotel yahoo domain
Code:
Dear Sir / Madam
The ItSecTeam has discovered a new bug in  PHP Classifieds Lastest Version and will be glad to report and public it .
More information about this bug is listed below :
=======================================================================================
Topic : PHP Classifieds Version 7.5
Bug type : Blind SQL Injection
Author : ItSecTeam
Remote : Yes
Status   : Bug
===================== Content ======================
( # Advisory Content : PHP Classifieds
( # Mail : Bug@ItSecTeam.com
( # Find By : Amin Shokohi(Pejvak!)
( # Special Tnx : M3hr@n.S , 0xd41684c654 And All Team Members!
( # Website : WwW.ItSecTeam.com
( # Forum : WwW.Forum.ItSecTeam.com

=================================================
============================================= Exploit 1 =======================================
( * http://localhost/phpClassifieds v7.5/ad_click.php?bid=2 SQL Injection Code
----------------------------------------------------------------------------------
<BUG>
  $bid=getParam("bid","");
if ($bid>0)
{
    $sql_banner = "SELECT goto_url FROM $banner_tbl WHERE bid=****$bid****";
........}
</Bug>
----------------------------------------------------------------------------------
===========================================================================================
  Reply With Quote
Sponsored Links
Reply

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump




Copywr0ng (c) 2009 Miercuri catre Joi - RST
All logos and trademarks in this site are property of their respective

Hosted by powerhost.ro