Owner-UnArm3D

Wednesday, 24 October 2012

Custom Upload SQL injection


Author --> NoEntryPhc
Vulnerability --> SQL Injection
Google Dork --> inurl:customupload.html
Vulnerable Link --> http://www.website.com/customupload.html?category=2

Finding vulnerable site -->

Search inurl:customupload.html in google and you will find many website. Open any of one like i have one link which is given below
Now add ' after link to find the vulnerability of website like this.
I you get any warning message like error in mysql database than website is vulnerable.

Exploting the vulnerability-->

Exploit the vulnerability manually or using software like Haviji
Download Haviji from here
Password for download and archieve is thedarkarea

0 comments:

Post a Comment

Comment for problems not for doing spam

Category 2

Category 3