Monday, 14 April 2014

Andhra Pradesh Grameena Vikas Bank is vulnerable to SQL injection

APGVB Formation




 By amalgamation, on the 31st March 2006, of the following 5 banks, sponsored by SBI, to participate more energetically, with synergy, in the uplift and development of Rural Farm Sector and Rural Non-Farm Sector, with emphasis on the deprived, the Rural Poor, Rural ISB and Rural Crafts.

 Further on testing i found vulnerability in http://www.apgvbank.in 


Hope they will patch the vulnerability  as soon as possible.





Regards:GD 5TT5CK3R


Friday, 11 April 2014

Jammu University is Vulnerable to SQL Injection

Ok Guys,Further on testing I found vulnerability in Jammu University



 



Regards: GD 4TT4CK3R

Thursday, 10 April 2014

Pakistan Geo Tv News is Vulnerable to XSS

Further on testing i found vulnerability in Geo TV News of Pakistan

Affected URL:   http://geo.tv/SearchNews.aspx?URL=%3Cscript%3Ealert%28%27test%27%29;%3C/script%3E







Regards:GD 4TT4CK3R

IIPM College is Vulnerable is XSS

Founded in 1973, The Indian Institute of Planning and Management has grown to become one of the most respected business schools in South Asia . Its unique focus on national economic planning and highly researched management process control techniques has rewarded it with having the most exhaustive linkages with all facets of the corporate world. The Integrated and Full Time Programme in National Economic Planning and Entrepreneurship provided by IIPM (which are superior to standard MBA and BBA programs), alongwith IIPM's Fellowship, Executive Education (and Global Opportunities and Threats Analysis programs where students visit organizations like the United Nations (Geneva), World Bank, ILO, Nestle S.A. Vevey, IMD Lausanne, Credit Suisse etc.) have created some of the highest standards in the management field.

Further on testing i found vulnerability








Regards: GD 4TT4CK3R

Wednesday, 9 April 2014

Nivia Sports is Vulnerable to XSS

NIVIA � India�s leading Sports Brand, influential and intimately involved in shaping the sports in the country. As the originator of breakthrough technologies & innovative products , for decades NIVIA has produced legendary classics and earned nation-wide legitimacy in each sport that it has participated in. Backed by generations of sportsmen, NIVIA is the true INDIAN Iconic Sports Brand. NIVIA is Indian leading manufacturer of sports equipment, footwear & accessories. Our core sports are Football, Volleyball, Basketball, Cricket, Tennis, Hockey, Badminton and Squash.
Established since 1934, NIVIA is Headquartered in Jalandhar, India, NIVIA employee force is more than 2000, our dedicated sales network spreads to more than 1200 Dealers across India.

NIVIA is an Freewill Sports Pvt Ltd Brand.

Further on testing i found xss 

Affected url:
http://www.niviasports.com/search.php?keywords=<script>alert('test')</script>
























Regards: GD 4TT4CK3R

Tuesday, 8 April 2014

Sumpoorna Portfolio Limited is Vulnerable to SQL injection

Sumpoorna Portfolio Limited (�Sumpoorna Stock�/ �The company�) represents the equities arm of the Sumpoorna group. The company is a corporate member of both The National Stock Exchange of India Limited and The Bombay Stock Exchange, providing equity broking and research services, and catering to retail clients, domestic and foreign institutional investors. The company is focused on providing products, strategies and services to Corporates, HNIs, and retail clientele. We have a pan-India presence through our various channels, providing clients with the tools and services they need to maximize their investments performance and attracting new sources of capital.
Sumpoorna Stock spearheads the Capital Markets broking division of the Group, which provides services range from offline & online trading in equity, commodities and currency derivatives to debt market. 












Regards by GD 4TT4CK3R


Saturday, 21 December 2013

Zee Cinema is Vulnerable to LFI(local file inclusion) + iframe Injection.

Local File Inclusion (LFI) is a type of vulnerability which is mostly found in websites. It allows hacker to include a local file, usually through a script on the web server. The vulnerability occurs due to the use of user-supplied input without proper validation.  LFI Vulnerability allows an attacker to add any local file to Website Server through script. LFI is very dangerous vulnerability which can lead to website Defacement, Command Execution and many more........

Here are some of the common parameters which are vulnerable to local file inclusion or remote file inclusion attacks

read.html?link=
index.php?homepage=index.php?

page=index.php?index2=

But recent days I was testing Zee Cinema for vulnerabilities and i found that it is vulnerable to local file inclusion.









Enjoy!!!!!!!!!!!!!