Classifieds Script – ‘rate’ SQL Injection

  • 作者: L0rd CrusAd3r
    日期: 2010-06-22
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/13971/
  • 1 ########################################## 1
    0 I'm L0rd CrusAd3r member from Inj3ct0r Team1
    1 ########################################## 0
    0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=1
    Author: L0rd CrusAd3r aka VSN [crusader_hmg@yahoo.com]
    Exploit Title:Classifieds SQL Injection
    Vendor url:http://getaphpsite.com
    Version:1
    Price:20$
    Published: 2010-06-22
    Greetz to:r0073r (inj3ct0r.com), Sid3^effects, MaYur, MA1201, M4n0j, Sonic Bluehat.
    Special Greetz: Topsecure.net, inj3ct0r Team , Andhrahackers.com
    Shoutzz:- To all ICW members.
    ~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~
    Description:
    
    Classifieds are an excellent revenue generator that brings sellers and buyers together. With our classifieds site, you can build revenues by offering a service that everyone can use.
    The classifieds site is a 100% automated site that allows seller to post ads based on categories. The site comes preprogrammed with PayPal and Stormpay as payment processors using the IPN system for a truly hands free experience.
    Sellers create an account and pick a package to post their ads that the admin specifies, which includes choosing from standard ads to featured ads that appear on the main webpage.
    This site also includes a rotating banner management system and newsletter that is easily moderated from the admin area.
    
    ~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~
    
    Vulnerability:
    
    *SQLi Vulnerability
    
    DEMO URL :
    
    http://server/classifieds/search.php?rate=[sqli]
    
    # 0day n0 m0re #
    # L0rd CrusAd3r #