Restaurant Listing with Online Ordering – SQL Injection

  • 作者: L0rd CrusAd3r
    日期: 2010-06-15
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/13884/
  • 1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-0
    0 _ __ __ __ 1
    1 /' \ __ /'__`\ /\ \__ /'__`\ 0
    0 /\_, \ ___ /\_\/\_\ \ \ ___\ \ ,_\/\ \/\ \ _ ___ 1
    1 \/_/\ \ /' _ `\ \/\ \/_/_\_<_ /'___\ \ \/\ \ \ \ \/\`'__\ 0
    0 \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/ 1
    1 \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ 0
    0 \/_/\/_/\/_/\ \_\ \/___/ \/____/ \/__/ \/___/ \/_/ 1
    1 \ \____/ >> Exploit database separated by exploit 0
    0 \/___/ type (local, remote, DoS, etc.) 1
    1 1
    0 [+] Site : Inj3ct0r.com 0
    1 [+] Support e-mail : submit[at]inj3ct0r.com 1
    0 0
    1 ########################################## 1
    0 I'm L0rd CrusAd3r member from Inj3ct0r Team 1
    1 ########################################## 0
    0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=1
    Author: L0rd CrusAd3r aka VSN [crusader_hmg@yahoo.com]
    Exploit Title:Restaurant Listing SQl Vulnerable
    Vendor url:http://www.webvolume.co.uk
    Version:n/a
    Price:n/a
    Published: 2010-06-15
    Greetz to:Sid3^effects, MaYur, M4n0j, Dark Blue, S1ayer,d3c0d3r,KD and to
    all ICW members.
    Spl Greetz to:inj3ct0r.com Team
    
    ~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~
    
    Own your own restaurant guide, with reviews, driving directions and
    pictures. This website allows you to charge the restaurant owners a fixed
    amount per year of a listing. It also gives you the option to offer basic
    listings (ones without pictures, opening hours etc) for free.
    
    Whats Included?
    
    # FREE business cards to advertise your new business/website
    # Full email support via our helpd desk for the life time of your website
    # Logo for your website
    # Your own domain name
    # Unlimited email addresses for your website
    # Unlimited email forwarders - so your website email can be forwarded to
    your existing email address
    # Unlimited web space - so as your site grows it will never run out of disk
    space
    # All money made from your website is yours to keep - it goes directly to
    your PayPal account
    # Free advertising and promotion guide
    # Free basic search engine submission for 1 month to get you started
    
    
    ~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~
    
    Vulnerability:
    
    *SQLi Vulnerability
    
    DEMO URL :
    
    http://server/TypeSearch.asp?typeID=[sqli]
    
    # 0day n0 m0re #
    # L0rd CrusAd3r #
    
    
    -- 
    With R3gards,
    L0rd CrusAd3r