Anyway, the MySQL>5 allows me to take all DB details and entities in it. Also, the admin panel is vulnerable to login bypass due to lack of filtration of the data.
Below is the screenshot of the logged panel:
Thank you and hope they fix it...
nepali security and hacking team ktm hackerz shares and informs the vulnerabilities in Nepali websites and webservers. The one and only blog of first nepali hackers group
Sorry forgot to quote sam for finding admin panel of the website...
ReplyDeletegood, i drop by here through keyword "sql injection" via a service call "blogger auto follow" im following u.. hope to see u in my followers list soon and would love to share anything from internet, network and information security stuff.
ReplyDeleteregards,
Hacking Expose! Team