Monday, October 20, 2014

Sum Technologies SQL Injection

source :

http://packetstormsecurity.com/files/127571/Sum-Technologies-SQL-Injection.html




# Exploit Author:Th3 R0cksT3r
# Exploit Title: Sum Technologies (id) SQL Injection Vulnerability
# Email: th3rockst3r@gmail.com
# Vendor Homepage: http://www.sumtechnologies.com/
# Google Dork: intext:"Powered by Sum Technologies"



Proof Of Concept:


1. https://server/elf_erecting.php?id=[SQL Injection]
2. http://server/index.php?do=view_model&id=[SQL Injection]
3. http://server/about.php?id=[SQL Injection]



# Greetz:Bangladesh Black HAT Hackers

0 komentar:

Post a Comment

I just a newbie and student, don't using this article for criminal