[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Scripts Genie Top Sites (out.php, id param) - SQL Injection Vulnerability
# Published : 2013-02-17
# Author :
# Previous Title : OpenPLI v3.0 beta (OpenPLi-beta-dm7000-20130127-272) - Multiple Vulnerabilities
# Next Title : CKEditor 4.0.1 - Multiple Vulnerabilities
##################################################################################
__ _ _ ____
/ /___ _____ (_)_____________ ______(_)__ _____ / __ _________ _
__ / / __ `/ __ / / ___/ ___/ __ `/ ___/ / _ / ___// / / / ___/ __ `/
/ /_/ / /_/ / / / / (__ |__ ) /_/ / / / / __(__ )/ /_/ / / / /_/ /
____/__,_/_/ /_/_/____/____/__,_/_/ /_/___/____(_)____/_/ __, /
/____/
##################################################################################
Top Sites Script, SQL Injection Vulnerabilities
Software Page: http://scriptsgenie.com/index.php?do=catalog&c=scripts&i=top_site_script
Product Page: http://www.hotscripts.com/listing/top-sites-2-2-1/
Script Demo: http://scriptsgenie.com/demo/toplist.2.11/toplist/index.php
Author(Pentester): 3spi0n
On Social: Twitter.Com/eyyamgudeer
Greetz: Grayhats Inc. and Janissaries Platform.
##################################################################################
[~] MySQL Injection on Demo Site (/out.php?id=)
>>> http://server/toplist/out.php?id=20' (MySQLi Found)