LY Network Cart suffers from a remote SQL injection vulnerability.
5408e58fc0afe9f33c3f527ad3ca278787a8e9726ee1238947cc8dc2cb78c893
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ __ __ 1
1 /' \ __ /'__`\ /\ \__ /'__`\ 0
0 /\_, \ ___ /\_\/\_\ \ \ ___\ \ ,_\/\ \/\ \ _ ___ 1
1 \/_/\ \ /' _ `\ \/\ \/_/_\_<_ /'___\ \ \/\ \ \ \ \/\`'__\ 0
0 \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/ 1
1 \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ 0
0 \/_/\/_/\/_/\ \_\ \/___/ \/____/ \/__/ \/___/ \/_/ 1
1 \ \____/ >> Exploit database separated by exploit 0
0 \/___/ type (local, remote, DoS, etc.) 1
1 1
0 [+] Official Website: http://www.1337day.com 0
1 [+] Support E-mail : mr.inj3ct0r[at]gmail.com 1
0 0
1 ########################################## 1
0 I'm NuxbieCyber Member From Inj3ct0r Team 1
1 ########################################## 0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1
[ LY Network Cart - SQL Injection Vulnerability ]
[x] Author : the_cyber_nuxbie
[x] Home : www.thecybernuxbie.com
[x] E-mail : staff@thecybernuxbie.com
[x] Found : 09 March 2012 @ 09:57 PM.
[x] Tested : Back|Track 5.
[x] Dork : inurl:"/pro.php?CateId="
________________________________________________________________________
************************************************************************
- Info WebApps:
Lian Ya Network Technology Co, Ltd © All Rights Reserved Telp: 020 -8,322,664,983,226,249
http://www.lywebsite.com/
- Exploit Report:
http://localhost/pro.php?CateId=[SQL Injection]
- Page LogIn:
http://localhost/site/manage/ <--- LogIn Area...!!!
- Sample WebApps Vuln SQLi:
http://risvision.cn/en/pro.php?CateId=18' + [SQL Injection]
http://agiftfromchina.com/pro.php?CateId=11' + [SQL Injection]
http://taobaoxpress.com/pro.php?CateId=4' + [SQL Injection]
http://top1rc.com/pro.php?CateId=150' + [SQL Injection]
http://zh318.com/en/pro.php?CateId=46' + [SQL Injection]
http://deniya.com/pro.php?CateId=39' + [SQL Injection]
http://ccs123.com/pro.php?CateId=1' + [SQL Injection]
http://romerigo.com/pro.php?CateId=85' + [SQL Injection]
http://yin-yuan.com.cn/en/pro.php?CateId=10' + [SQL Injection]
http://ystuliao.com/pro.php?CateId=79' + [SQL Injection]
http://1000cch.com/pro.php?CateId=34' + [SQL Injection]
http://cgcguitar.com/pro.php?CateId=83' + [SQL Injection]
http://haotaofishing.com/en/pro.php?CateId=12' + [SQL Injection]
http://3150.com/pro.php?CateId=4' + [SQL Injection]
http://romerigo.com/pro.php?CateId=122' + [SQL Injection]
http://wartonclutch.com/pro.php?CateId=19' + [SQL Injection]
http://longa99.com/en/pro.php?CateId=17' + [SQL Injection]
http://sunwefashion.com/pro.php?CateId=26' + [SQL Injection]
http://fwsewing.com/en/pro.php?CateId=101' + [SQL Injection]
http://paint-by-frank.com/pro.php?CateId=48' + [SQL Injection]
http://yonesnav.com/en/pro.php?CateId=6' + [SQL Injection]
http://risumtech.com/pro.php?CateId=41' + [SQL Injection]
, And Many More @ Google...!!!
0day no more...
"n0 d0rk f0r k1dd10ts"
- Curahan Hati:
I want to school college level...
(the biggest obsession = S1 - TI)
But I do not have a cost...
Help Me...!!!
- Greetz:
*** 1337day Inject0r TEAM ***
...:::' All Member & Staff Inject0r TEAM ':::...
- Greetz To All Exploiters From Indonesian:
[ Member Of Inj3ct0r & Exploit-DB ]
Akatsuchi, AntiSecurity, Arianom, bius, blackraptor, bumble_be, c4uR, cr4wl3r, cyberlog, Don Tukulesto, EA Ngel,
eidelweiss, Flyff666, g3mbeLz_YCL, Gendenk, gunslinger_, h4ntu, IbnuSina, irvian, Jack, k3m4n9i, k1ngk0n9, k1tk4t,
k4mtiez, K-159, kecemplungkalen, Mask_magicianz, MISTERFRIBO, M3NW5, Mbah_Semar, mywisdom, Newbie Campuz, NoGe,
NTOS-Team, Oli Bekas, OoN_Boy, Pokeng, r3m1ck, S3T4N, s4va, sikunYuk, SENOT, skulmatic, spykit, Sudden_death,
team_elite, tempe_mendoan, the_day, tomplixsee, v3n0m, vir0e5, Vrs-hCk, vYc0d, Xr0b0t, y3d1ps, etc...
"Kalian Telah Mengharumkan Nama INDONESIA Di Dunia IT-Underground"
Me @ March, 09 2012, GMT +09:57 Solo Raya, Indonesian.