Loading....
Loading....

    Posted by unu in English News

    Posted on December 4th, 2008

    Se pare ca nu doar sentimente.ro are probleme de securitate, ci si un alt site de dating cu trafic frumusel.
    Parametrul viewprofile.php?id= fiind vulnerabil la blind sql injection, se pot extrage cu usurintza tabele bazei de date.

    Database: dating
    114 tabele
    +—————————–+
    | pro_account_alerts
    | pro_active_sessions
    | pro_addition_info_content
    | pro_advices
    | pro_advices_categories
    | pro_badwords
    | pro_banners_area
    | pro_banners_belongs_to_area
    | pro_banners_sizes
    | pro_banners_table
    | pro_billing_country
    | pro_billing_entry
    | pro_billing_paysystems
    | pro_billing_send_requests
    | pro_billing_unit
    | pro_billing_user_account
    | pro_billing_user_period
    | pro_blacklist
    | pro_blog_main
    | pro_blog_settings
    | pro_city_spr
    | pro_country_spr
    | pro_descr_spr
    | pro_descr_spr_match
    | pro_descr_spr_user
    | pro_descr_spr_values
    | pro_distance_spr
    | pro_fc_bans
    | pro_fc_bot
    | pro_fc_bots
    | pro_fc_connections
    | pro_fc_conversationlog
    | pro_fc_dstore
    | pro_fc_gmcache
    | pro_fc_gossip
    | pro_fc_ignors
    | pro_fc_messages
    | pro_fc_moderators
    | pro_fc_patterns
    | pro_fc_rooms
    | pro_fc_templates
    | pro_fc_thatindex
    | pro_fc_thatstack
    | pro_gallary
    | pro_gallary_rating
    | pro_group_module
    | pro_group_period
    | pro_groups
    | pro_height_spr
    | pro_horoscope_signs
    | pro_hotlist
    | pro_im_ignore
    | pro_im_list
    | pro_im_message
    | pro_interests_spr
    | pro_interests_spr_match
    | pro_interests_spr_user
    | pro_kisslist
    | pro_language
    | pro_language_spr
    | pro_mailbox
    | pro_module_file
    | pro_module_statistic
    | pro_modules
    | pro_nationality_spr
    | pro_news
    | pro_news_feeds
    | pro_nl_attach
    | pro_nl_click_counter
    | pro_nl_clients_lists
    | pro_nl_clients_releases
    | pro_nl_creleases
    | pro_nl_creleases_lists
    | pro_nl_form
    | pro_nl_forms_lists
    | pro_nl_list
    | pro_nl_release_attach
    | pro_nl_settings
    | pro_nl_smtp_server
    | pro_nl_snd_users
    | pro_nl_templates
    | pro_online_notice
    | pro_personality_spr
    | pro_personality_spr_match
    | pro_personality_spr_user
    | pro_personality_spr_values
    | pro_portrait_spr
    | pro_portrait_spr_match
    | pro_portrait_spr_user
    | pro_portrait_spr_values
    | pro_profile_visit
    | pro_reference_lang_spr
    | pro_region_spr
    | pro_relationship_spr
    | pro_savesearch
    | pro_savesearch_descr
    | pro_settings
    | pro_subscribe_system
    | pro_subscribe_user
    | pro_success_stories
    | pro_take_tour
    | pro_templates
    | pro_themes
    | pro_user
    | pro_user_comment
    | pro_user_group
    | pro_user_match
    | pro_user_profile
    | pro_user_rating
    | pro_user_topten
    | pro_user_types_spr
    | pro_user_upload
    | pro_video_codes
    | pro_weight_spr
    +—————————–+

    La fel de usor se pot extrage si datele de logare a userilor, cat si a adminilor.

    Related Posts

    One Response to “Dating.acasa.ro blind sql injection”

    1. Alex Says:

      Salut!
      Cum se pot extrage datele de logare a userelor?astept raspuns.Ms

    Leave a Reply