Burmese Classic

PlanetCreator has reported another critical Blind SQL Injection (vulnerability) on http://www.burmeseclassic.com/

This vulnerability has been alerted to :- Webmaster of BurmeseClassic

Applications: ———— PlanetCreator’s_Universal_Advanced_Internet_Security_T00L
System Time: ———— (UTC+08:00) Yangoon, Myanmar , 07/08/2010 02:28:46 AM

Database :————- burmesec_pawtin

Tables :—————-

youth_qna
youth_news
youth_corner
video_review
video
users
thuta
tayar
sports
song
servers
sayadaw
news
mtv_thingyan
mtv
movies
movie_rate
message
left_menu
health
files
ebook_writer
ebook
dhamma_qus
dhamma_ans
comment
cartoon
buddhawin
baydin_qus
baydin_ans
banned_users
active_users
active_guests

Columns of users table

userip
timestamp
email
userlevel
userid
password
username

username    — password

bcadmin    —–  (just for vip members)

We hope that your security staff will look into this issue and fix it as soon as possible.

Explore More

SQL Commandos (usefull for injections)

Here is a list of SQL commands and what they do, these would be used in some injection methods and of course legitimate sql functions. On thier own they wont

How to send fake emails from any email address

Firstly this isnt my tutorial and i just found it on the net so please dont say that i stole someone elses tutorial. And I dont know if someone has

ModSecurity

ModSecurity is a web application firewall (WAF). With over 70% of attacks now carried out over the web application level, organisations need all the help they can get in making