[<prev] [next>] [day] [month] [year] [list]
Message-ID: <x2xf5ac9ad81004081115ud87035a8m1a3ce06ef626d8dd@mail.gmail.com>
Date: Thu, 8 Apr 2010 14:15:49 -0400
From: Malice Anonymous <malice.anon@...il.com>
To: full-disclosure@...ts.grok.org.uk
Subject: www.Demolay.org - full disclosure sql injection
vulnerability
Vulnerable URL
/d_wnl_ads/?did=14&dc=1&gid=28
Users:
demolaymain
demolaystore
phpmyadmin
root
Tables from DEMOLAY database
ADVISOR_TYPE......WORK_GROUP_PERMISSION (75 tables)
This ought to be fixed, SWIM tells me there's tons of personal stuff in
these tables.
Content of type "text/html" skipped
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists