Business Classified Listing – SQL Injection

  • 作者: L0rd CrusAd3r
    日期: 2010-06-15
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/13883/
  • Author: L0rd CrusAd3r aka VSN [crusader_hmg@yahoo.com]
    Exploit Title:Business Classified Listing SQl Vulnerable
    Vendor url:http://www.webvolume.co.uk
    Version:8
    Price:n/a
    Published: 2010-06-15
    Greetz to:Sid3^effects, MaYur, M4n0j, Dark Blue, S1ayer,d3c0d3r,KD and to
    all ICW members.
    Spl Greetz to:inj3ct0r.com Team
    
    ~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~
    
    Description:
    
    Own your own business guide/directory, with reviews, driving directions and
    pictures. This website allows you to charge the restaurant owners a fixed
    amount per year of a listing. It also gives you the option to offer basic
    listings (ones without pictures, opening hours etc) for free.
    
    Whats Included?
    
    # FREE business cards to advertise your new business/website
    # Full email support via our helpd desk for the life time of your website
    # Logo for your website
    # Your own domain name
    # Unlimited email addresses for your website
    # Unlimited email forwarders - so your website email can be forwarded to
    your existing email address
    # Unlimited web space - so as your site grows it will never run out of disk
    space
    # All money made from your website is yours to keep - it goes directly to
    your PayPal account
    # Free advertising and promotion guide
    # Free basic search engine submission for 1 month to get you started
    
    ~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~
    
    Vulnerability:
    
    *SQLi Vulnerability
    
    DEMO URL :
    
    http://server/TypeSearch.asp?typeID=[sqli]
    
    # 0day n0 m0re #
    # L0rd CrusAd3r #
    
    
    -- 
    With R3gards,
    L0rd CrusAd3r