header-logo
Suggest Exploit
vendor:
PRE PRINTING STUDIO website script
by:
r45c4l
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: PRE PRINTING STUDIO website script
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012

PRE PRINTING STUDIO Sql Injection

A SQL injection vulnerability exists in the PRE PRINTING STUDIO website script. An attacker can exploit this vulnerability by sending malicious SQL queries to the vulnerable page. This can allow the attacker to gain access to sensitive information such as usernames, passwords, and other confidential data stored in the database.

Mitigation:

Input validation should be used to prevent SQL injection attacks. All user-supplied input should be validated and filtered before being used in an SQL query.
Source

Exploit-DB raw data:

# Exploit Title:   PRE PRINTING STUDIO Sql Injection
# Date: 16/03/2012
# Author: r45c4l
# Email: infosecpirate@gmail.com
# Script url: http://www.preprojects.com/preprojects/printing.asp 
# Version: N/A
# CVE : ()

::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

Product Description : 

A complete printing press website script contains all features required for online printing business. Developed in PHP, MYSQL and Flash AS3, with all browsers compatibility and easy to navigate. Package contains builtin designers to customize designs online, shopping cart and complete users and orders modules.Product is user friedly and can fully operate via secure admin panel.Script is fully customizable and ready to upload to start your printing press now.


Product Cost : 999$ 



=================Exploit=================================================
                                    ---ICW---
 [ EXPL0!T ]

 SQL Injection
 p0c - http://SERVER/prestudio/page.php?id=[SQli] 


 d0rk - use your brain ;) 


 Some intresting tables and columns: 

 Table : admin 		Columns : password, username, id 

 Table : users		columns : email, id

===========================================================================
Greetz to : Beenu Arora, Godwin Austin, Eberly, b0nd, the_empty_, micr0, Hoody, sam
            All members of ICW, AH and G4H, and all Indian Hackers


                    
Special Greetz to :  b4ltazar and s1nn3r
			

									=== End () ====