City Directory Review and Rating Script – ‘search.php’ SQL Injection

  • 作者: 3spi0n
    日期: 2012-12-24
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/23623/
  • # Exploit Title: City Directory Review and Rating Script SQL Injection
    Vulnerability
    # Date: 22.12.2012
    # Author: 3spi0n
    # Script Vendor or Software Link:
    http://b-scripts.com/en/18-city-reviewer-yelp-clone.html
    # Category: WebApps
    # Type: SQL Injection [MySQLi]
    # Tested On: Ubuntu 12.10 - Win7
    
    =================================================
    # Demo: http://b-scripts.com/demo/city_reviewer/
    
    # MySQLi Detected On:
    http://server/city_reviewer/search.php?category=6
    
    
    =================================================
    
    # My Blog: www.Ryuzaki.in
    # Social : Twitter.com/bariiiscan
    # My Team: Grayhatz Inc. & Agedz Corp.
    # Turkey.