2 SQL Injection in d3jeeb
Date: 26 Feb 2006 21:16:13 -0000
From: [email protected]
To: [email protected]
Subject: 2 SQL Injection in d3jeeb
X-Virus-Scanned: antivirus-gw at tyumen.ru
Software: D3Jeeb
Web Site: http://www.tl4s.com
Versions: tested on D3Jeeb Pro 3
Type: SQL Injection
Class: Remote
Vulnerable script:
fastlinks.php
catogary.php
Exploit :
1-
http://www.target.com/fastlinks.php?catid=[SQL]
2-
http://www.target.com/catogary.php?catid=[SQL]
Discovered by: SAUDI
L-G-H Team
http://www.lezr.com
Regards ///