37 lines
No EOL
1.8 KiB
Text
37 lines
No EOL
1.8 KiB
Text
Name : I-net Multi User Email Script SQLi Vulnerability
|
|
Date : june, 27 2010
|
|
Critical Level : HIGH
|
|
Vendor Url : http://www.i-netsolution.com/
|
|
Google Dork: inurl:/jobsearchengine/
|
|
Author : Sid3^effects aKa HaRi <shell_c99[at]yahoo.com>
|
|
special thanks to : r0073r (inj3ct0r.com),L0rd CruSad3r,MaYur,MA1201,KeDar,Sonic,gunslinger_
|
|
greetz to :www.topsecure.net ,All ICW members and my friends :) luv y0 guyz
|
|
#######################################################################################################
|
|
|
|
Description:
|
|
i-Net Multi User Email Script to start your own Email Website like GMAIL, YAHOO Mail, Hot Mail made in CGI/PERL, tested over Linux
|
|
|
|
Servers. Features of i-Net Multi User Email Script, Advanced Spam Filtering, RBL Blacklisting, Completely MIME compatible, Contact List
|
|
|
|
Members Filter Proof, Multiple Skins, Limit Users Outgoing Mail (Depending on User Level) Sort Inbox With Several Criteria, Fully
|
|
|
|
customizable via HTML templates, Mod_Perl Compatible, New Mail Sounds, WYSIWYG Mail Interface, Multiple Tiered Premium Accounts, Premium
|
|
|
|
Accounts using Paypal & Subscriptions, SMTP or Send mail, Fully functional calendar and scheduler, Unlimited User Folders, Folder Filtering
|
|
|
|
(Incoming mail directed to specific folders), Email notifications of new mail, MySQL backend, Backup, Powerful Admin Panel, Ban IP, Advanced
|
|
|
|
User Editing, Account Suspensions, User Address Book, i-Net Talk and many more features.
|
|
|
|
#######################################################################################################
|
|
|
|
Xploit: SQLi VUlnerability
|
|
|
|
|
|
The I-net Multi User Email Script has SQli vuln :D
|
|
|
|
DEMO URL : http://server/products/2daybizemail/php121_editname.php?uid=[sqli]
|
|
|
|
###############################################################################################################
|
|
# 0day no more
|
|
# Sid3^effects |