Hosting Syste-Mar SQL Injection

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1047294 漏洞类型
发布时间 2012-06-12 更新时间 2012-06-12
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2012060127
|漏洞详情
漏洞细节尚未披露
|漏洞EXP

==> ABOUT ME:
--- TAURUS OMAR
--- INDEPENDENT SECURITY RESEARCHER
--- ACCESOILEGAL.BLOGSPOT.COM
--- @omartaurus
--- omar-taurus[at]dragonsecurity[dot]org 
--- omar-taurus[at]live[dot]com
 
===> INFO:
Author        : TAURUS OMAR
Category      : Webapps / 0day 
Title Exploit : Hosting Syste-Mar - SQL Injection Vulnerability 
Vendor        : Hosting Syste-Mar
URL Vendor    : http://www.syste-mart.com/
Google Dork   : intext:"Hosting Syste-Mart" 


==> SAMPLE'S SQLi:
http://www.entremodelos.com.mx/verModelo.php?id=28  [SQL Injection]
http://www.piccola.com.mx/verLinea.php?id=3  [SQL Injection]
http://www.puntoforza.com/verLinea.php?id=19  [SQL Injection]
http://www.puntoforza.com/verLinea.php?id=19  [SQL Injection]
http://laglorietachapalita.com/verObra.php?idObra=388&id=82  [SQL Injection]


MORE IN GOOGLE..